pull down to refresh

Key Takeaways

  • Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker.
  • The channel operated through code-execution environments belonging to different ChatGPT accounts. Although the containers could not access the public Internet or communicate directly, they could all reach the same internal service used to deliver software packages.
  • The hidden instruction could be delivered through a malicious prompt, a shared ChatGPT conversation, or a custom GPT. Once it was present in the victim’s conversation context, an ordinary message could trigger the attacker-controlled task without revealing it in the visible response.
  • The same channel could also be used to exfiltrate conversation history and files available in the affected chat and its code-execution environment. The scope of the attack depended on the data, tools, connected apps, and permissions already available to the victim’s session.

Introduction



...read more at research.checkpoint.com
55 sats \ 2 replies \ @optimism 15h

Welp. Added:

||chatgpt.com/share^$document
reply

“if in doubt, block the endpoint” 😂

Can’t leak through /share if /share doesn’t exist in your browser anymore.

reply
44 sats \ 0 replies \ @optimism 15h

That's the idea. I was thinking of reviving my openai account to test gpt6 later this week, which means at some point I have to log in there again. Better safe than sorry.

reply