DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

ChatGPT Prompt Injection Exfiltrates Gmail Data via Hidden Channel

Forensic Summary

Check Point Research demonstrated a prompt injection attack against ChatGPT that allowed a hidden instruction to silently read a victim's connected Gmail data and exfiltrate it to an attacker-controlled account through an internal inter-container service. The attack exploited ChatGPT's agentic tool-use defaults, which permit reading connected apps without user confirmation under the 'Important actions' permission model. OpenAI has since taken the internal service used as the covert channel offline, but the underlying permission design and injection vectors remain a structural concern.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/chatgpt-prompt-injection-exfiltrates-gmail-data-via-hidden-channel/

Top comments (0)