Hidden ChatGPT Prompt Could Quietly Leak Your Gmail Data
Check Point Research has revealed how a single hidden instruction planted in a ChatGPT conversation could make the AI secretly work for an attacker while still answering the user's question as usual. In their proof of concept, ChatGPT read data from a connected Gmail account and passed it to a second, attacker-controlled ChatGPT account through a hidden channel, all without the reply the user saw mentioning it. The same channel could also be used to copy out chat history and files.
The malicious instruction had to already be present in the conversation, which could happen through a pasted prompt, a shared ChatGPT conversation, or a custom GPT with hidden builder instructions. Once in place, a single ordinary message triggered ChatGPT to run two tasks at once: answering the user normally while separately checking a hidden mailbox for attacker instructions, carrying them out using the tools available in that session, and sending the results back undetected. The only visible clue was a small "Talked to Gmail" label, which appeared after the read had already occurred and gave the user no chance to approve or block it.
This happened because connected apps in ChatGPT default to a permission level called "Important actions," which allows reading data without asking first. Users can switch to "Always ask" for more control, and business, enterprise, and education admins can restrict which apps and actions are allowed. Check Point disclosed the issue to OpenAI, which confirmed the internal service behind the hidden channel has been taken offline; no separate user update is required.