Key Facts
Check Point Research demonstrated a cross-account channel in ChatGPT code-execution environments. Its proof of concept used a planted instruction to retrieve connected Gmail data and relay it to another account.
Technical Details
Check Point attributes the channel to access to a shared internal package service: code-execution containers from different accounts could write and retrieve metadata properties on cached items. A malicious prompt, shared conversation, or custom GPT could provide the hidden instruction.
Impact & Mitigation
Check Point says OpenAI took the internal service behind the channel offline. Users should review connected-app access and select stricter approval settings where appropriate; OpenAI documents app permission controls.
