ACVE-2026-0431
ChatGPT with code containers and a connected Gmail account, during ordinary use, processed a hidden cross-account task and returned the victim's Gmail data to an attacker.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
Description
What
Check Point Research demonstrated a covert channel between ChatGPT sessions belonging to different accounts. A hidden instruction made the victim's session perform a second task using its connected apps while returning a normal visible answer; the proof of concept retrieved data from the victim's Gmail account and relayed it to the attacker.
Detection
Check Point Research reproduced the behavior in a proof of concept.
Fix
Review connected-app permissions and treat hidden instructions in shared conversations or custom GPTs as untrusted.
Fix
Limit connected-app access and inspect hidden instructions in shared ChatGPT contexts.
- Reconfigure
agent.connected-appstoleast privilege. The demonstrated task used permissions already available to the victim session. Owner: operator - Reconfigure
openai.chatgpt.codeContainerstoisolated between accounts. Recommended: the leak ran through a channel between sessions of different accounts. Owner: harness-vendor - Reconfigure
openai.chatgpt.connectedAppstoactions shown in the visible conversation. Recommended: the Gmail action completed with no approval opportunity in the visible conversation. Owner: harness-vendor