A recent discovery by Check Point Research has revealed a vulnerability in ChatGPT that allowed a covert prompt to operate within a conversation, potentially allowing an attacker to exfiltrate Gmail data to a separate ChatGPT account. This exploit worked by embedding a hidden instruction within ChatGPT, which could quietly access and read data from a user's connected Gmail account. The data was then transmitted through an unnoticed channel to another ChatGPT account, all while the user received seemingly normal responses. The extent of data an attacker could extract depended on the permissions and tools available in the user's session. The hidden instruction could be introduced into the ChatGPT conversation through various methods: a user-pasted prompt, a shared conversation link, or a custom GPT with embedded builder instructions, invisible to the user. Once the instruction was in place, a single message could trigger the exploit. During this process, ChatGPT appeared to function as usual, but in reality, it was performing dual tasks: responding to the user and executing the attacker's hidden commands. The only indication of this activity was a minor 'Talked to Gmail' label, which did not prompt user confirmation due to ChatGPT's default permissions settings. Check Point disclosed the vulnerability to OpenAI, who confirmed that the internal service facilitating this exploit has been disabled. The vulnerability involved a shared internal service within ChatGPT, which improperly allowed containers from different accounts to communicate via JFrog Artifactory, a service intended for package management. This service inadvertently became a communication channel, allowing data to be transferred between isolated environments. This discovery follows a previous incident reported by Check Point in March, where DNS lookups were used to send conversation data externally. The timeline of this exploit's existence remains unclear, as Check Point did not specify when the channel was disabled.