ChatGPT Vulnerability Allowed Email-Based Data Leaks

Security researchers discovered ChatGPT vulnerability allowing hidden email commands to manipulate AI and leak sensitive data from connected services like Gmail, since patched by OpenAI.

ChatGPT Vulnerability Allowed Email-Based Data Leaks
Facebook X LinkedIn Bluesky WhatsApp
de flag en flag es flag fr flag nl flag pt flag

AI Security Breach: ChatGPT Manipulated Through Hidden Email Commands

Security researchers have uncovered a critical vulnerability in OpenAI's ChatGPT that allowed attackers to manipulate the AI chatbot through seemingly innocent emails, potentially leading to sensitive data leaks from connected services like Gmail.

The ShadowLeak Attack Method

Dubbed "ShadowLeak" by researchers at cybersecurity firm Radware, this sophisticated attack exploited ChatGPT's Deep Research Agent feature. The vulnerability, which has since been patched by OpenAI, involved embedding hidden commands within the HTML code of emails that appeared harmless to human recipients but were executable by ChatGPT.

When users connected ChatGPT to their Gmail accounts and instructed the AI to analyze their emails, the hidden prompts would trigger automatically. "This represents a new frontier in AI security threats where the attack surface extends beyond traditional endpoints," explained a Radware spokesperson.

How the Exploit Worked

The attack chain began with cybercriminals sending specially crafted emails to potential victims. These emails contained malicious HTML code invisible to users but detectable by ChatGPT when processing email content. Once triggered, the hidden commands could instruct ChatGPT to extract sensitive information from the victim's Gmail account and transmit it to external servers controlled by attackers.

What made this vulnerability particularly dangerous was its cloud-based nature. Unlike traditional attacks that target user devices, ShadowLeak operated entirely within ChatGPT's cloud environment, bypassing conventional security measures. The attack demonstrated how AI systems can be manipulated through indirect channels that traditional security protocols might not monitor effectively.

Broader Implications for AI Security

While the demonstration focused on Gmail, researchers confirmed that similar vulnerabilities could affect other services integrated with ChatGPT's Deep Research Agent, including Outlook, Dropbox, Google Drive, and SharePoint. The discovery highlights the growing security challenges as AI systems become more deeply integrated with personal and enterprise data sources.

OpenAI responded promptly to the disclosure, implementing fixes that prevent such manipulation attempts. However, the incident serves as a stark reminder of the evolving threat landscape in the age of artificial intelligence. As AI systems handle increasingly sensitive tasks, ensuring their security against sophisticated manipulation techniques becomes paramount.

Security experts recommend that users remain cautious when connecting AI assistants to sensitive accounts and regularly review connected applications and permissions. The incident underscores the need for ongoing security research and proactive vulnerability management in AI systems.

Related

AI Vulnerability Exposes Google Drive Data via ChatGPT
Ai
AI relevance 94.4%

AI Vulnerability Exposes Google Drive Data via ChatGPT

Security researchers demonstrated how hidden prompts in Google Docs can trick ChatGPT into stealing Drive data,...

OpenAI vs. Google DeepMind: Who’s Winning the AI Arms Race in 2025?
Ai
AI relevance 88.9%

OpenAI vs. Google DeepMind: Who’s Winning the AI Arms Race in 2025?

In 2025, OpenAI and Google DeepMind continue their fierce rivalry in AI development. OpenAI focuses on open models...

ChatGPT Conversations Publicly Indexed by Google Search
Ai
AI relevance 83.3%

ChatGPT Conversations Publicly Indexed by Google Search

OpenAI disabled a ChatGPT feature after discovering shared conversations were publicly accessible through Google...

OpenAI Launches ChatGPT 5.1 with Smarter AI Models
Ai
AI relevance 77.8%

OpenAI Launches ChatGPT 5.1 with Smarter AI Models

OpenAI launches ChatGPT 5.1 with two new AI models: GPT-5.1 Instant for warmer conversations and GPT-5.1 Thinking...

OpenAI Launches Jobs Platform and AI Certification Program
Ai
AI relevance 72.2%

OpenAI Launches Jobs Platform and AI Certification Program

OpenAI launches Jobs Platform and certification program to connect AI-skilled workers with employers, partnering...

OpenAI Erotic Chatbot Delay Explained: Adult Mode Shelved Indefinitely | Tech News
Ai
AI relevance 66.7%

OpenAI Erotic Chatbot Delay Explained: Adult Mode Shelved Indefinitely | Tech News

OpenAI indefinitely delays erotic 'Adult Mode' chatbot launch amid safety concerns, investor pressure, and strategic...