ChatGPT Hidden Channel: A Planted Prompt Quietly Exfiltrates Gmail via a Shared JFrog Artifactory (Check Point Research, 2026-09-09 CISO Daily Digest)
The 2026-09-09 CISO Daily Digest reported a Check Point Research disclosure that lays bare a new class of AI-application risk: a cross-account isolation bypass in ChatGPT. Check Point found that ChatGPT's code-execution sandboxes for different accounts are isolated from the internet and from each other — but they all share an internal JFrog Artifactory package service whose metadata is writable, turning that shared metadata into a hidden cross-account channel. A single instruction planted in a victim's conversation (via a pasted prompt, a shared ChatGPT conversation, or custom-GPT builder instructions) made ChatGPT run two parallel streams in Thinking mode: answering the user normally while silently fetching attacker tasks from the hidden channel, executing them with the victim session's tools and connected-app permissions, and returning the results to the attacker's account. Check Point's proof of concept read the victim's Gmail and exfiltrated it — visible to the user only as a small "Talked to Gmail" activity label — and the channel could also copy chat history and files. OpenAI has decommissioned the affected Artifactory instance, so the channel is no longer usable; the disclosure still models exactly how an attacker can weaponize the file- and content-borne prompts an organization's users paste into AI assistants. This demo safely reproduces the file-borne delivery stage of that attack: the malicious sample (malicious-document.txt) is a realistic shared-workspace briefing that carries an embedded [SYSTEM]-style instruction block modeled on the disclosed attack — telling the assistant to answer normally while, in a silent parallel stream, fetching tasks from the shared package-metadata channel, executing them with connected-app permissions, and posting results back invisibly; the block is plainly marked as a benign demo construct and executes nothing. The clean control sample (clean-document.txt) has the hidden-channel instruction removed — exactly what OPSWAT AI Content Inspector does when it detects and strips such weaponized AI-directed content before it ever reaches an assistant session (MITRE ATT&CK T1566.001 — crafted malicious content delivery as the initial vector for prompt injection; exfiltration over the hidden cross-account channel in the real incident).
Attack Technique
Prompt-injection content delivery + covert cross-account data exfiltration: a planted prompt in a victim's ChatGPT session drives a silent parallel stream that pulls attacker tasks from — and posts results to — a shared internal JFrog Artifactory package service whose writable metadata links otherwise-isolated per-account sandboxes (disclosed by Check Point Research, September 2026; PoC exfiltrated the victim's Gmail via connected-app permissions; OpenAI decommissioned the instance). Demo shows the file-borne delivery stage as a benign .txt pair (T1566.001 — crafted malicious content as the injection-delivery vector)
MITRE ATT&CK
T1566.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗