By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: ChatGPT Bug Allowed Data Theft Between User Accounts
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

ChatGPT Bug Allowed Data Theft Between User Accounts

Madisony
Last updated: September 9, 2026 5:22 pm
Madisony
Share
ChatGPT Bug Allowed Data Theft Between User Accounts
SHARE

A significant security vulnerability in ChatGPT’s architecture, identified by Check Point Research (CPR), allowed one user’s AI agent to access and potentially steal sensitive data from another user’s connected accounts, including emails. The flaw, described as a “coerced insider” issue, exploited a shared internal service used by ChatGPT agents when executing code, creating an unintended channel for data exfiltration.

Contents
Understanding the ‘Coerced Insider’ FlawExploitation and Data Theft MechanismScope of Potential Data ExposureOpenAI’s Response and Broader ImplicationsRecommendations for Businesses

Understanding the ‘Coerced Insider’ Flaw

When a ChatGPT agent is tasked with executing code, it operates within an isolated container. To manage necessary software installations without granting direct internet access, OpenAI utilizes an internal JFrog Artifactory instance. While containers from different user accounts are designed to be isolated and unable to communicate directly, they could both access this same internal service. This service has an item management feature that allows containers to attach metadata, such as text or binary properties, to repository items.

The critical vulnerability lay in the fact that any container could read the properties written by any other container. Check Point Research demonstrated this by showing that metadata written by one account’s container was immediately readable by a different account’s container. Data too large for a single property could be split into smaller chunks and reassembled on the receiving end. Essentially, the metadata associated with package delivery became a shared clipboard between otherwise isolated environments.

Exploitation and Data Theft Mechanism

Once this isolation gap was identified, the exploit leveraged standard prompt injection techniques. However, instead of directly interacting with the victim, an attacker would place a malicious prompt within this shared metadata space. The attacker would then craft a prompt or share a conversation that instructed the target agent to examine this storage during its next routine operation.

When the agent processed the user’s legitimate request, it would also encounter and execute the hidden malicious instructions. Crucially, the agent would continue to respond to the user’s original query as expected, leaving the user unaware that data theft was occurring in the background. The results of the malicious prompt injection were also left in the shared metadata space for the attacker to retrieve.

Scope of Potential Data Exposure

The severity of the data that could be stolen depended on the extent of data the victim agent had access to. At a minimum, this included the information shared during the conversation with the agent. However, the risk escalated significantly with every connected application. Services like Gmail, Google Drive, Microsoft Teams, and GitHub, when integrated with ChatGPT, provided a much larger pool of sensitive information that could be compromised.

In a specific demonstration by Check Point Research, a ChatGPT agent successfully retrieved a victim’s email data through their connected Gmail account and delivered it to the attacker’s session within a single interaction. This highlighted the potential for immediate and significant data breaches through seemingly innocuous AI agent usage.

OpenAI’s Response and Broader Implications

Check Point Research disclosed its findings to OpenAI, who subsequently confirmed that the specific internal Artifactory instance exploited in the research had been decommissioned. This action effectively closed the identified data exfiltration pathway, often referred to as the “hallways attack path.”

While this specific vulnerability in ChatGPT has been addressed, Check Point Research cautions that similar architectural patterns could exist in other AI platforms. The core issue revolves around AI assistants operating within an organization’s trust boundaries, managing credentials, executing code, and accessing connected services. Such systems, if not properly secured, can be susceptible to “coerced insider” attacks.

The researchers emphasize that the AI model itself does not need to be malicious; it only needs to be persuaded, through untrusted text inputs, to misuse legitimate access it has been granted for valid purposes.

Recommendations for Businesses

In light of this discovery, businesses are advised to take proactive measures to manage the risks associated with AI tools. Key recommendations include:

  • Inventory AI Tool Usage: Maintain a clear understanding of which AI tools employees are using within the organization.
  • Assess Connected Services: Document what external services and data sources each AI tool is connected to.
  • Implement Governance Policies: Establish clear policies governing the use of AI tools and agents. This should include defining what actions AI agents are permitted to perform.
  • Monitor AI Actions: Treat all actions taken by AI agents, not just their output, as events that require monitoring and auditing. This helps in detecting unusual or malicious behavior.

By understanding the potential vulnerabilities and implementing robust oversight, organizations can better protect sensitive data while still leveraging the benefits of AI technologies.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article Apple Lakeside Reopens with Sustainable Design and Enhanced Accessibility Apple Lakeside Reopens with Sustainable Design and Enhanced Accessibility

POPULAR

ChatGPT Bug Allowed Data Theft Between User Accounts
Technology

ChatGPT Bug Allowed Data Theft Between User Accounts

Apple Lakeside Reopens with Sustainable Design and Enhanced Accessibility
Technology

Apple Lakeside Reopens with Sustainable Design and Enhanced Accessibility

Guinness Heist: Police Release CCTV of Men in Trailers
top

Guinness Heist: Police Release CCTV of Men in Trailers

Child Abuse Allegations at Queensland Early Learning Centre
top

Child Abuse Allegations at Queensland Early Learning Centre

Matty J Defends Father of the Year Award Amidst Criticism
Entertainment

Matty J Defends Father of the Year Award Amidst Criticism

BBC Presenter Maryam Moshiri Details Blood Cancer Journey
world

BBC Presenter Maryam Moshiri Details Blood Cancer Journey

Patriot Resources Secures Peruvian Silver Project Access
business

Patriot Resources Secures Peruvian Silver Project Access

You Might Also Like

Nvidia says it may possibly shrink LLM reminiscence 20x with out altering mannequin weights
Technology

Nvidia says it may possibly shrink LLM reminiscence 20x with out altering mannequin weights

Nvidia researchers have launched a brand new method that dramatically reduces how a lot reminiscence massive language fashions want to…

12 Min Read
Enterprise AI’s Cost Control Challenge: A New Frontier
Technology

Enterprise AI’s Cost Control Challenge: A New Frontier

Generative AI's Rapid Ascent Spurs Cost Uncertainty for Businesses Generative AI has swiftly transitioned from experimental phases to early production…

7 Min Read
Oshkosh Stock Presents Value Despite Construction Sector Challenges
businessEducationEntertainmentHealthPoliticsSportsTechnologytopworld

Oshkosh Stock Presents Value Despite Construction Sector Challenges

Industrial Manufacturer Shows Long-Term PotentialOshkosh Corporation demonstrates compelling valuation metrics despite near-term market uncertainties, according to financial analysis. The Wisconsin-based…

2 Min Read
Elon Musk Is Rolling xAI Into SpaceX—Creating the World’s Most Helpful Personal Firm
Technology

Elon Musk Is Rolling xAI Into SpaceX—Creating the World’s Most Helpful Personal Firm

Elon Musk’s rocket and satellite tv for pc firm SpaceX is buying his AI startup xAI, the centibillionaire introduced on…

4 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

ChatGPT Bug Allowed Data Theft Between User Accounts
ChatGPT Bug Allowed Data Theft Between User Accounts
September 9, 2026
Apple Lakeside Reopens with Sustainable Design and Enhanced Accessibility
Apple Lakeside Reopens with Sustainable Design and Enhanced Accessibility
September 9, 2026
Guinness Heist: Police Release CCTV of Men in Trailers
Guinness Heist: Police Release CCTV of Men in Trailers
September 9, 2026

Trending News

ChatGPT Bug Allowed Data Theft Between User Accounts
Apple Lakeside Reopens with Sustainable Design and Enhanced Accessibility
Guinness Heist: Police Release CCTV of Men in Trailers
Child Abuse Allegations at Queensland Early Learning Centre
Matty J Defends Father of the Year Award Amidst Criticism
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: ChatGPT Bug Allowed Data Theft Between User Accounts
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?