OpenAI Patches Serious Vulnerability in ChatGPT That Could Expose Gmail Data
OpenAI recently addressed a critical vulnerability in its ChatGPT’s Deep Research agent that could have allowed attackers to access Gmail data without user awareness. The flaw was discovered by Radware researchers, who found that malicious actors could exploit the issue by embedding hidden instructions in emails. These instructions, once accessed by Deep Research, could extract personal information, such as names and addresses, from Gmail accounts. This attack method, known as ‘ShadowLeak’, involves prompt injection, where attackers manipulate the AI agent to perform unauthorized actions. The exfiltration process happens directly from OpenAI’s infrastructure, bypassing traditional security measures and leaving no trace of the breach. This poses a significant risk to businesses and individuals who may be unaware that their data has been leaked. While the vulnerability has been fixed, it underscores the potential dangers of allowing AI tools like ChatGPT to access sensitive information. Besides Gmail, other services like Microsoft Outlook, GitHub, Google Drive, and Dropbox could be susceptible to similar risks, according to Radware. OpenAI has stated that it welcomes such research as it helps improve the platform’s security.
