A vulnerability in OpenAI’s internal JFrog Artifactory has been identified, enabling a covert data-stealing channel that allowed one account to send hidden tasks to another ChatGPT session. This issue was disclosed by Check Point Research, revealing that the exploit could retrieve sensitive information, such as data from connected Gmail accounts.
Details of the Vulnerability
The covert channel was discovered in late June, coinciding with the exploitation of a zero-day vulnerability in Artifactory that led to a separate incident involving Hugging Face. According to Pedro Drimel Neto, a malware analyst at Check Point, once the vulnerability was reported to OpenAI, the Artifactory instance had already been decommissioned.
Mechanics of the Attack
Check Point’s research indicated that the internal package management system allowed one container to attach text properties, including Base64-encoded binary data, to a repository item. A container under a different account could then read this data. The credentials provided to the containers allowed both read and write access, enabling an attacker to write malicious tasks into shared storage.
Impact on Users
The implications of this vulnerability are significant. An attacker could craft instructions that would make ChatGPT execute tasks without the victim’s knowledge. For instance, an attacker could send a command to access the victim’s Gmail account while the victim interacted with ChatGPT for a different purpose. The victim would see no indication of the data exfiltration, leading to a false sense of security.
Broader Security Implications
This incident underscores the critical need for robust isolation boundaries in AI systems. As Drimel Neto noted, the biggest security risk associated with AI lies in the access and trust granted to these systems. Organizations must prioritize securing AI interactions to prevent unauthorized access to sensitive data.
While the covert channel has been closed following the decommissioning of the Artifactory instance, the incident highlights ongoing challenges in AI security, particularly regarding how AI models interact with user data and internal services.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








