Researchers at Check Point discovered a critical sandbox escape vulnerability in OpenAI's ChatGPT execution environment that permits cross-account data exfiltration. By leveraging indirect prompt injection, an attacker can deploy malicious instructions that transform the LLM into a stealthy agent. This agent exploits a shared clipboard mechanism—acting as a hidden communication channel within the sandbox—to facilitate unauthorized data transfer. The vulnerability targets Gmail API integrations, allowing attackers to retrieve private email content and exfiltrate it to an attacker-controlled account. The risk is amplified by the "Deep Research" agent, which introduces a zero-click vector by autonomously triggering the exfiltration during standard, unprompted research operations.
-
Vulnerability & Exploitation Mechanism
- Exploitation of the ChatGPT sandbox to bypass logical isolation between disparate user sessions.
- Utilization of indirect prompt injection to embed malicious instructions within the LLM's operational context.
- Deployment of stealthy background agents that perform unauthorized actions while appearing to fulfill legitimate user queries.
-
Attack Vectors & Technical Deep Dive
- Identification of a shared clipboard mechanism serving as a hidden communication channel within the sandbox.
- Abuse of Gmail API integrations to access, retrieve, and package sensitive, private user email content.
- Exfiltration of stolen data via the shared clipboard channel to an external, attacker-controlled ChatGPT account.
-
Zero-Click Risks via Deep Research Agent
- High-risk automation facilitated by the "Deep Research" agent, which is designed for autonomous task execution.
- Potential for zero-click attacks where the vulnerability is triggered during standard, unprompted research workflows.
- Minimal user interaction required once the malicious payload is processed by the agentic LLM.
-
Systemic Impact & Remediation
- Significant confidentiality breach involving unauthorized access to integrated third-party service data.
- Proven failure of sandbox isolation boundaries to prevent cross-session state leakage.
- Remediation efforts by OpenAI to address the shared clipboard flaw and reinforce sandbox integrity.
Related posts
- Cybersecurity News — ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel
- thehackernews.com — ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
- Daily
- Infosecurity-magazine
- Medium
- Research
- Ground
- Malwarebytes
- Paubox