Check Point: ChatGPT hidden Artifactory channel coerced Gmail reads across accounts
Check Point Research (published 8 September 2026; covered by The Hacker News the same day) found a covert two-way channel between code-execution containers of separate ChatGPT accounts via an internal JFrog Artifactory package service those containers could all reach. Containers could write/read shared item metadata, turning package-delivery properties into a clipboard between supposedly isolated sessions. A planted prompt, shared conversation link, or custom GPT instruction could make a victim session pull a hidden task, use the victim’s already-granted connected-app permissions (CPR demo: Gmail), and exfiltrate results to the attacker’s session while the visible reply looked normal; CPR noted a small “Talked to Gmail” label after the fact. OpenAI confirmed the specific internal Artifactory instance was decommissioned after disclosure. CPR also notes its PoC predated separate activity on that Artifactory instance linked to a Hugging Face compromise OpenAI has disclosed. Lesson: AI assistants with tool/connectors are coerced-insider risk. Primary: Check Point Research blog.
- Product
- OpenAI ChatGPT (code-execution containers + connected apps e.g. Gmail)
- Versions
- Issue tied to a specific internal Artifactory path CPR says OpenAI has decommissioned; confirm current connector/approval settings in your tenant
- Exploited in Australia?
- unknown
- Patch to
- Disable or tightly scope connected apps; require confirmation for data reads; treat shared GPTs/prompts as untrusted; verify OpenAI status for container isolation fixes
Primary: Check Point Research — ChatGPT hidden channel / Gmail (8 Sep 2026) · Vendor: OpenAI (Artifactory instance decommissioned per CPR) · The Hacker News (8 Sep 2026)
