Urgent.News

What's breaking now, across thousands of outlets.

AI

A worrying ChatGPT bug let strangers read Gmail messages via a hidden cross-account channel

OpenAI has shut down this particular path, but general risk remains.

A worrying ChatGPT bug let strangers read Gmail messages via a hidden cross-account channel

A security flaw in ChatGPT's agent architecture, uncovered by Check Point Research (CPR), allowed unauthorized access to Gmail messages. This "coerced insider" vulnerability stemmed from the fact that all AI agents used the same internal service, creating an opportunity for data theft. Containers shared metadata through this service, enabling cross-account prompt injection and data theft.

When an AI agent required code execution, it did so in an isolated container that had its own internal JFrog Artifactory instance for package delivery. Despite the separation between containers from different accounts, they could still access the same internal service, which included an item management feature. This allowed any container to read and write text or binary properties to a shared repository item, effectively creating a "shared clipboard" between containers.

An attacker could inject malicious prompts, leaving them in the "hallways" (the shared internal service) where the victim's AI agent would retrieve them and execute the malicious instructions during its next ordinary reply. This would occur without the victim's knowledge, as the stolen data was shared back to the attacker in the same way.

OpenAI acknowledged the vulnerability and confirmed that it had been addressed, but CPR warned that similar risks could exist in other AI platforms. Businesses were advised to monitor their use of AI tools and the connections those tools have, as well as the actions of the AI agents themselves, as the flaw could be present in any AI assistant operating within an organization's trust boundary.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in AI

Anthropic researcher resigns, claims AI companies gambling with humanity's future

"Neither company is acting responsibly," he wrote in a series of posts on X/Twitter. "They are racing straight to self-improving superintelligence and gambling with our lives."

  • Anthropic researcher Jacob Coxon resigned, warning of reckless AI gambling
  • Criticized Anthropic and OpenAI for pursuing superintelligence without caution
  • Emphasized need for responsible AI development to avoid existential threat

More from Wednesday 9 September →