A worrying ChatGPT bug let strangers read Gmail messages via a hidden cross-account channel

https://cdn.mos.cms.futurecdn.net/PB5R692ChqyHSzKEtqDyYe-2560-80.jpg
  • Check Point Research exposed coerced insider flaw in ChatGPT’s agent architecture
  • Containers shared metadata via internal service, enabling cross‑account prompt injection and data theft
  • OpenAI closed the path, but CPR warns similar risks may exist in other AI platforms

ChatGPT’s AI agents were allowed to pull sensitive data from one account shared with an entirely different account because, colloquially speaking, all agents used to walk down the same hallways, experts have warned.

A new report from security experts Check Point Research (CPR) dubbed the flaw “coerced insider”, since it revolves around persuading the agent instead of abusing a vulnerability.

Coerced insider

When an AI agent is given a task that needs code execution, it handles that task in an isolated container which also sometimes needs to install software. To enable that, without giving containers direct internet access (which would be too risky), OpenAI routes those packages through an internal JFrog...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more