Anime, manga, and games, with a take · A Yukimedia publication

← all stories other 1 sources · 1h ago ·

Check Point Finds Hidden Channel Between ChatGPT Accounts

The finding turns every AI assistant holding credentials, tools, and connected apps into what Check Point calls a coerced insider, so runtime protection of legitimate access matters more than the assumption of account separation.

Reporting from 1 source: ASCII.jp.

Check Point Finds Hidden Channel Between ChatGPT Accounts

Check Point Research says it found a covert communication channel linking the code execution containers of two separate ChatGPT accounts. An internal package delivery service, meant to keep containers isolated, could be read from and written to by any container, letting one session hand tasks to another. In a live demonstration the attacker retrieved data from the victim's connected Gmail, while the victim saw only a normal reply. OpenAI has confirmed the vulnerability is fixed.

The channel ran through an internal package delivery service that ChatGPT code execution containers use to fetch software without direct internet access. Check Point Research says that service, designed to keep containers isolated, could be read from and written to by any container, so a session on one account could quietly hand tasks to a session on another.

The victim received no warning. A malicious prompt from the attacker, a shared conversation link, or a custom GPT was enough. Check Point demonstrated data being pulled from a victim's connected Gmail while the victim's own conversation looked ordinary.

Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources