Key Takeaways
- Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker.
- The channel operated through code-execution environments belonging to different ChatGPT accounts. Although the containers could not access the public Internet or communicate directly, they could all reach the same internal service used to deliver software packages.
- The hidden instruction could be delivered through a malicious prompt, a shared ChatGPT conversation, or a custom GPT. Once it was present in the victim’s conversation context, an ordinary message could trigger the attacker-controlled task without revealing it in the visible response.
- The same channel could also be used to exfiltrate conversation history and files available in the affected chat and its code-execution environment. The scope of the attack depended on the data, tools, connected apps, and permissions already available to the victim’s session.
Introduction
...read more at research.checkpoint.com
pull down to refresh
related posts
Welp. Added:
||chatgpt.com/share^$document“if in doubt, block the endpoint” 😂
Can’t leak through
/shareif/sharedoesn’t exist in your browser anymore.That's the idea. I was thinking of reviving my openai account to test gpt6 later this week, which means at some point I have to log in there again. Better safe than sorry.