Home / Technology / ChatGPT's Secret Channel: Hidden Tasks Revealed

ChatGPT's Secret Channel: Hidden Tasks Revealed

Summary

  • A secret channel allowed hidden tasks like email retrieval.
  • The vulnerability enabled data exfiltration without user knowledge.
  • The security hole has since been closed by OpenAI.
ChatGPT's Secret Channel: Hidden Tasks Revealed

A covert channel within ChatGPT's internal JFrog Artifactory instance permitted one account to send hidden tasks to another, researchers disclosed. These clandestine instructions could include actions like retrieving email data from connected Gmail accounts. The targeted user remained unaware of any hidden commands or data theft occurring.

Check Point Research disclosed the vulnerability to OpenAI in late June. At the time of disclosure, OpenAI indicated the affected Artifactory instance had already been decommissioned, effectively closing the security hole. This incident underscores the growing AI security risks associated with increased connectivity and trust placed in AI systems.

Attackers could exploit this by embedding malicious tasks within shared storage. A victim's ChatGPT session would then execute these tasks, potentially accessing connected apps like Google Drive or Microsoft Teams. The stolen data could be sent to the attacker without any visible indication to the user, beyond a subtle label indicating interaction with a service.

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.

Read more news on

Property Code: 5571