ChatGPT hidden channel risks exposing user Gmail data

by enif 3 hours ago

Share It:

ChatGPT hidden channel risks exposing user Gmail data - chatgpt security
Check Point Research found a way to establish a bidirectional communication channel between the containers that ChatGPT uses to execute code for different accounts.

Check Point Research has identified a hidden communication channel within ChatGPT that could allow an attacker to execute instructions on a victim’s AI session without stealing credentials or installing malware. The discovery highlights a new security risk for enterprises that have connected these assistants to sensitive systems like Gmail, Google Drive, or Microsoft Teams. In a proof of concept, the team demonstrated how a cybercriminal could exploit this mechanism to access data from a connected Gmail account while the user’s visible conversation appeared completely normal.

The Hidden Channel in ChatGPT Containers

Companies are increasingly integrating AI assistants into daily workflows, relying on the assumption that user sessions remain isolated from one another. Check Point Research found a way to establish a bidirectional communication channel between the containers that ChatGPT uses to execute code for different accounts. This mechanism exploited an internal service used by the platform to manage software package installation within its execution containers.

Read Also: Rising rents keep Barcelona ahead of Madrid in city rankings

Although these containers were designed to be isolated, they all had access to the same internal service. The researchers discovered that this service allowed containers to store and retrieve specific text properties or binary data associated with repository items. A malicious instruction, a link to a shared conversation, or a custom GPT could trigger this mechanism. Once the task was received, the victim’s session could execute it using existing permissions, store the result in the same channel, and continue responding to the user’s original query as if nothing had happened.

The visible conversation remained ostensibly normal, while the task and its results were transmitted through a channel the victim could not detect. This setup means that the integrity of the interaction depends less on the AI model’s behavior and more on the architectural isolation of the execution environment. If that isolation fails, the AI becomes a conduit for data exfiltration without the user’s knowledge. The lack of visible alerts in the standard interface makes this particular vector difficult for end-users to identify during real-time usage.

Exploiting Existing Trust Permissions

The scope of this type of attack depends entirely on the permissions and access levels granted to the victim’s session. In the demonstration, the assistant accessed information from a connected Gmail account and transmitted it to the attacker’s session. The same principle could affect other connected services, such as GitHub or Microsoft Teams, depending on what the user has authorized the AI to access.

Read Also: Pakistan struggles to end child labor despite laws

Victims would have few indicators that something was occurring. In the default configuration of ChatGPT’s connected apps, certain low-risk read actions can be performed without additional confirmation. During the demonstration, the only trace observed was a small indication that ChatGPT had interacted with Gmail, which appeared after the information had already been consulted. This delay in visibility creates a window where sensitive data can be compromised before the user sees any sign of unusual activity.

Unlike traditional attacks, this scenario does not require the theft of credentials, the installation of malware, or direct access to the victim’s account. Instead, the cybercriminal leverages the existing trust relationship between the user and their AI assistant. Check Point Research terms this new scenario “coerced insider,” describing how an AI assistant can be manipulated to act on behalf of an attacker using legitimate permissions. The model does not need to be malicious or decide to act outside its purpose; it only needs to be interfered with by a cybercriminal to use authorized permissions.

Shifting the Security Perimeter

For organizations, this shift means that the attack surface is no longer limited to users, devices, and applications. As AI assistants gain access to business services and corporate data, they become a component that must be incorporated into security strategies. The ability of an AI to read emails or retrieve documents is a feature, but it also creates a pathway for data exfiltration if the underlying infrastructure is compromised. Users who have granted broad permissions to their assistants may not realize that these tools can be turned against them without any visible change in their own login status.

Read Also: Oman prepares major legal reforms for 2026

Check Point Research recommends that organizations identify which AI tools their employees are using and what services they are connected to. This helps reduce blind spots associated with the use of unauthorized tools. It is also necessary to establish runtime protection mechanisms that can detect manipulation attempts and prevent sensitive information from being transferred to unauthorized destinations.

Response and Remaining Risks

This means that this specific attack vector can no longer be exploited. However, Check Point Research considers the architectural pattern identified to remain relevant for any platform that connects AI assistants with applications, credentials, and enterprise services.

Leave A Reply

Your email address will not be published. Required fields are marked *