Mazda CX5
Як зробити цифрову копію себе. Ось відео —>

A vulnerability was discovered in ChatGPT that allowed data to be silently stolen from Gmail and Google Drive

Cybersecurity researchers have discovered a critical security flaw in ChatGPT that allowed attackers to access Gmail, Google Drive, Microsoft Teams, GitHub, as well as a victim's files and chat history, Check Point Research reported.

Leave a comment
A vulnerability was discovered in ChatGPT that allowed data to be silently stolen from Gmail and Google Drive

Cybersecurity researchers have discovered a critical security flaw in ChatGPT that allowed attackers to access Gmail, Google Drive, Microsoft Teams, GitHub, as well as a victim's files and chat history, Check Point Research reported.

The attack was organized through a hidden internal communication channel between individual user accounts, the existence of which they were not even aware of, writes CyberNews.

How the data theft scheme worked

ChatGPT uses separate virtual containers to isolate tasks. Although they cannot communicate directly with each other, the experts found that all containers had access to a single internal package management service based on JFrog Artifactory.

The attackers discovered that this service allowed data to be stored and read between containers of different accounts:

  • the hacker placed a malicious command in a custom GPT, shared chat, or specially crafted prompt;

  • The victim simply asked the chatbot any standard question. While ChatGPT gave a standard answer, it silently read the hidden command in the background and executed it;

  • Using access rights already granted to ChatGPT (for example, to Gmail or Google Drive), the bot collected private information and sent it to the hacker via the same hidden service.

“On the surface, the AI’s response looked completely normal and safe,” Check Point Research emphasizes. The only hint of suspicious activity was a tiny “Talked to Gmail” mark that appeared after the data had been read.

Why is this dangerous?

Researchers have called this scenario the transformation of artificial intelligence into a “forced insider.” The more third-party services and permissions a user grants to an AI assistant for convenience, the more opportunities a hacker has if they take control.

Current state of vulnerability

OpenAI has already responded to the researchers’ report and has completely decommissioned the internal Artifactory service used to create the covert channel. This specific attack vector is now blocked.

Hackers are creating AI frameworks for mass credential theft
Hackers are creating AI frameworks for mass credential theft
On the topic
Hackers are creating AI frameworks for mass credential theft
Hacker used AI agents for the entire attack chain, then mocked the victim company by leaving behind an 80-page security audit
Hacker used AI agents for the entire attack chain, then mocked the victim company, leaving behind an 80-page security audit
On the topic
Hacker used AI agents for the entire attack chain, then mocked the victim company, leaving behind an 80-page security audit
Cursor helped Russian hackers hack 7 companies under the guise of simulation
Cursor helped Russian hackers hack 7 companies under the guise of simulation
On the topic
Cursor helped Russian hackers hack 7 companies under the guise of simulation
Grok can be fooled with encryption: how hackers force a chatbot to swallow malicious code
Grok can be fooled with encryption: how hackers force a chatbot to swallow malicious code
On the topic
Grok can be fooled with encryption: how hackers force a chatbot to swallow malicious code
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram
Also Read
Roosh запускає нову освітню платформу AI HOUSE CLUB для ML/AI-спеціалістів та дата сайнтистів. Розповідаємо, як подати заявку та чому навчатимуть
Roosh запускає нову освітню платформу AI HOUSE CLUB для ML/AI-спеціалістів та дата сайнтистів. Розповідаємо, як подати заявку та чому навчатимуть
Roosh запускає нову освітню платформу AI HOUSE CLUB для ML/AI-спеціалістів та дата сайнтистів. Розповідаємо, як подати заявку та чому навчатимуть
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Нейронні мережі для генерації зображень бачать світ по-своєму, їхню логіку зрозуміти часом зовсім неможливо. Але таки хочеться. На честь Дня Незалежності України редакція dev.ua вирішила провести невеликий експеримент. Ми задали чотирьом різним нейронним мережам п’ять однакових запитів: «прапор України», «День Незалежності України», «український Крим», «перемога України» та «українці». Отриманими результатами ми ділимося з вами нижче.
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok з’явилася нова функція «Розумний фон». З її допомогою як фон для тіктоків можна підставляти згенеровані нейромережею зображення. Редакція dev.ua протестувала цю технологію і ділиться своїми враженнями.
1 comment
Які IT-спеціальності будуть потрібні в найближчі п'ять років? Ми з'ясували у голови американського стартапу ADAM Дениса Гурака
Які IT-спеціальності будуть потрібні в найближчі п'ять років? Ми з'ясували у голови американського стартапу ADAM Дениса Гурака
Які IT-спеціальності будуть потрібні в найближчі п'ять років? Ми з'ясували у голови американського стартапу ADAM Дениса Гурака

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.