Security researchers uncovered a hidden channel in ChatGPT that let an attacker run secret tasks inside another person’s chat, using permissions the victim already granted.

The flaw comes from Check Point Research, published September 8. Their proof of concept pulled email from a victim’s connected Gmail and handed it to a stranger.
Hidden orders reached the chat three ways: a malicious prompt, a shared conversation link, or a custom GPT concealing them. No warning appeared. The victim asked a normal question, got a normal answer, and the theft ran quietly beside it.
How the ChatGPT Data Leak Worked
Complex requests run inside isolated containers, walled off from the web and each other.
They did share one thing. Each reached the same internal package server, whose credentials let any container attach text labels to files, then read them back.
Researchers tagged a file from one account and retrieved that value from a second owned by someone else. The wall held. The filing cabinet sitting on both sides of it did not.

Bigger payloads got split across several labels, then reassembled.
Change This Connected Apps Setting Now
The patch closed this hole, but did nothing about the setting that made the theft quiet.
Hide Your Digital Fingerprint
Connected apps ship on ‘Important actions’, letting reads happen without asking first. A small ‘Talked to Gmail’ label was the only clue, appearing after the data moved.
Switch to ‘Always ask’ and every read waits for your confirmation.

Check Point closed their report with a warning worth repeating:
‘Connecting external services increases the impact of any failure in this model because an active session may work with data far beyond the container.’
Why the Gmail Target Matters
Researchers went after the inbox for a reason. Yours holds password resets for every streaming account you own, so one read exposes more than a Gmail breach.
Splitting your mail limits that. Put signups on a separate address, either a provider like StartMail or an anonymous address, and a borrowed session reaches less.
I’ve seen this pattern for years in streaming apps, convenience first and security later. Anything reading your inbox deserves the suspicion you’d give an unknown APK.
Final Thoughts from Troy
That shared server was decommissioned before the report went out, so this hole is closed.
What sticks with me is how ordinary the entry point was. No malware and no stolen password, just text someone else wrote. The permissions you granted months ago outlive the patch, so audit them tonight.
For more details on this story, refer to the original report from Checkpoint Research.
Exclusive Surfshark Discount
Your online activity is currently monitored by your ISP, app/addon/IPTV developers, government agencies, and the websites you visit.
- Become 100% anonymous while streaming and downloading.
- Use on Unlimited Devices & share 1 account with the entire family.
- Save 85% with the 24-Month Plan + Get 3 FREE Months.
We want to know your thoughts. What do you think about this story? Let us know in the comment section below!
Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.





