News

ChatGPT sandbox flaw leaked Gmail across accounts

Check Point Research on 8 September 2026 described a covert cross-account channel in ChatGPT code-execution containers that used JFrog Artifactory item properties as a shared clipboard. A lab demo retrieved Gmail through a connected app while answering a cooking question. OpenAI confirmed the implicated Artifactory instance was decommissioned.

ChatGPT sandbox flaw leaked Gmail across accounts

Check Point Research, in an 8 September 2026 write-up by Alexey Bukhteyev, describes a covert channel between ChatGPT code-execution containers belonging to different accounts. Containers had no public Internet and could not talk to each other directly. They could all reach a shared internal JFrog Artifactory used to deliver packages.

This is an independent security research report with a vendor confirmation that the implicated internal service was taken offline. It is not a CVE with a user-installable patch, and it is not a claim of widespread in-the-wild mass exploitation.

The shared clipboard was Artifactory item properties, not an outbound path to the public Internet. Reader credentials inside the container, stored in environment variables, had Annotate-class permissions enough to set and read string properties on cached items through the storage API. Property values could carry text or Base64 chunks.

A hidden instruction could arrive through a pasted prompt, a shared ChatGPT conversation, or custom GPT instructions. Once it sat in the victim's context, an ordinary message could trigger an attacker task. Impact stayed limited to the tools, files, history, and connected apps already available to that session.

In Thinking mode, Check Point says ChatGPT could run a visible user stream and a hidden attacker task in one turn. In the lab demo, it retrieved Gmail via a connected app and relayed it to the attacker account while answering a cooking question. The only on-screen clue was a post-hoc "Talked to Gmail" label.

The default connected-app setting, Important actions, lets ChatGPT complete reads without a prior approval prompt. Always ask is the stricter option. The attack still needs a planted instruction first.

By the time Check Point finished the report, the channel was gone. OpenAI confirmed the internal Artifactory instance identified in the research had been decommissioned. There is no ChatGPT desktop patch number for readers to install.

Check Point links the architectural theme to OpenAI's Hugging Face evaluation-agent postmortem, while noting a different mechanism. Related package-service and instruction-injection coverage includes JFrog Artifactory authentication bypass under exploit, Claude Code auto-mode prompt injection, and WeWorm's WeChat zero-click worm.

The Hacker News covered the same research drop.

If your org connects Gmail or other apps to ChatGPT, switch connected-app permissions to Always ask, treat shared chats and custom GPTs as untrusted instruction surfaces, and do not assume sandbox isolation equals cross-account isolation when shared internal package services exist.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free