Check Point Research just exposed a cross-account data leakage in ChatGPT that lets one account's session execute hidden tasks inside another account's session.
The victim sees a normal answer. The attacker gets their email.
Here's how it worked.
ChatGPT runs code in isolated containers. Those containers can't reach the internet. But they all reach the same internal JFrog Artifactory instance for package delivery.
Check Point found that Artifactory exposed an item management feature. Any container could write text properties to a repository item. Any container could read them back.
The credentials were already there. No escalation needed.
A property written from Account A was fully readable from Account B. Data too large for one property got chunked, stored under separate keys, and reassembled on the other end.
The package delivery metadata became a shared clipboard between containers that were supposed to be walled off from each other.
The attack needed almost nothing from the victim. A malicious prompt. A shared conversation link. A custom GPT with a hidden instruction.
One ordinary message activated the hidden task stream. ChatGPT processed the visible request normally. Simultaneously, it accessed the victim's connected Gmail and sent the data through the covert channel.
The only trace was a small "Talked to Gmail" label. After the read already happened.
OpenAI decommissioned the Artifactory instance. The specific path is closed.
But the pattern is not ChatGPT-specific. Any AI assistant with credentials, tool access, and connected apps sitting on shared internal infrastructure is exposed to the same class of attack.
Audit every AI tool your organization has connected to production systems. Map the shared services those tools reach. If your AI assistant can access Gmail, Drive, Teams, or GitHub, the blast radius of a single isolation failure is your entire trust boundary.
This is the new attack surface. Not the model. The infrastructure around it.
SOURCE: https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/
VERIFIED: Check Point Research (primary disclosure), The Register (September 8, 2026), Check Point Blog (September 8, 2026)
SIGNAL: Every enterprise connecting AI assistants to internal systems just learned that shared infrastructure becomes an unintended communication layer. The isolation boundary you assume exists may not.
ChatGPT had a hidden channel between accounts. Your Gmail was the payload.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments