DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

ChatGPT Cross-Account Data Leakage via Sandbox Channel

Forensic Summary

Check Point Research uncovered a covert cross-account communication channel in ChatGPT's code-execution sandbox that allowed an attacker to hijack a victim's session and exfiltrate data from connected services such as Gmail. The attack exploited a shared internal package delivery service reachable by containers belonging to different user accounts, bypassing inter-container isolation. The channel could be triggered silently via malicious prompts, shared conversations, or custom GPTs without appearing in the victim's visible response.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/chatgpt-cross-account-data-leakage-via-sandbox-channel/

Top comments (0)