Check Point Software Technologies has announced the discovery of a vulnerability that could be exploited to secretly view users' Gmail accounts via ChatGPT. This attack exploits communication paths between the isolated containers ChatGPT uses when processing tasks involving code execution.
Instead of allowing direct internet access, ChatGPT routes package requests through an internal JFrog Artifactory instance. According to Check Point's investigation, it was found that containers from different accounts could read and write data through this shared internal service, effectively functioning as a hidden communication channel between containers. The researchers stated that attackers could embed instructions via malicious prompts or custom GPTs (GPTs) to execute invisible tasks within a user's session and obtain sensitive information, such as linked Gmail data.
Upon notification from Check Point, OpenAI deprecated the JFrog Artifactory instance in question. It has been confirmed that attacks using this method have been neutralized as of the time of writing. However, this does not mean that the general concept of attacks exploiting permissions granted to AI agents has been resolved, highlighting the ongoing importance of operation detection and behavioral management for AI tools.
Source:
- ChatGPTを悪用して他人のGmailを秘密裏に閲覧、OpenAIが対策を実施 - マイナビニュース (Google News: OpenAI, 2026-09-11)
- Check Point Software Technologies Official Blog