Наталя ХандусенкоAI Eng
11 September 2026, 13:14
2026-09-11
A vulnerability was discovered in ChatGPT that allowed data to be silently stolen from Gmail and Google Drive
Cybersecurity researchers have discovered a critical security flaw in ChatGPT that allowed attackers to access Gmail, Google Drive, Microsoft Teams, GitHub, as well as a victim's files and chat history, Check Point Research reported.
Cybersecurity researchers have discovered a critical security flaw in ChatGPT that allowed attackers to access Gmail, Google Drive, Microsoft Teams, GitHub, as well as a victim's files and chat history, Check Point Research reported.
The attack was organized through a hidden internal communication channel between individual user accounts, the existence of which they were not even aware of, writes CyberNews.
How the data theft scheme worked
ChatGPT uses separate virtual containers to isolate tasks. Although they cannot communicate directly with each other, the experts found that all containers had access to a single internal package management service based on JFrog Artifactory.
The attackers discovered that this service allowed data to be stored and read between containers of different accounts:
the hacker placed a malicious command in a custom GPT, shared chat, or specially crafted prompt;
The victim simply asked the chatbot any standard question. While ChatGPT gave a standard answer, it silently read the hidden command in the background and executed it;
Using access rights already granted to ChatGPT (for example, to Gmail or Google Drive), the bot collected private information and sent it to the hacker via the same hidden service.
“On the surface, the AI’s response looked completely normal and safe,” Check Point Research emphasizes. The only hint of suspicious activity was a tiny “Talked to Gmail” mark that appeared after the data had been read.
Why is this dangerous?
Researchers have called this scenario the transformation of artificial intelligence into a “forced insider.” The more third-party services and permissions a user grants to an AI assistant for convenience, the more opportunities a hacker has if they take control.
Current state of vulnerability
OpenAI has already responded to the researchers’ report and has completely decommissioned the internal Artifactory service used to create the covert channel. This specific attack vector is now blocked.
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Нейронні мережі для генерації зображень бачать світ по-своєму, їхню логіку зрозуміти часом зовсім неможливо. Але таки хочеться. На честь Дня Незалежності України редакція dev.ua вирішила провести невеликий експеримент.
Ми задали чотирьом різним нейронним мережам п’ять однакових запитів: «прапор України», «День Незалежності України», «український Крим», «перемога України» та «українці». Отриманими результатами ми ділимося з вами нижче.
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok з’явилася нова функція «Розумний фон». З її допомогою як фон для тіктоків можна підставляти згенеровані нейромережею зображення. Редакція dev.ua протестувала цю технологію і ділиться своїми враженнями.