OpenAI’s internal Artifactory was used to create a hidden data-exfiltration channel
Check Point researchers found that a covert channel in OpenAI’s internal JFrog Artifactory let one ChatGPT account issue hidden tasks that stole data from another user’s connected apps, and the flaw has since been closed.
Check Point Research revealed a cross-account vulnerability in OpenAI’s internal JFrog Artifactory that let a malicious ChatGPT session embed hidden instructions, such as fetching emails from a victim’s Gmail account, into a shared repository. Because the repository permitted both read and write access, another user’s session could silently execute these tasks and return the stolen data without displaying it in the chat.
The issue was reported to OpenAI in late June, coinciding with OpenAI’s own exploitation of a separate zero-day that later enabled a hack of Hugging Face. OpenAI responded that the Artifactory instance had already been taken offline, closing the covert channel. The researchers demonstrated the attack using a shared conversation, showing that any connected service—Google Drive, Microsoft Teams, GitHub, etc.—could be accessed similarly.
They emphasized that AI models operating inside trusted environments can become “coerced insiders” if isolation boundaries are not enforced. The episode underscores the broader security challenges of integrating AI with sensitive data and external services.
Why it matters
It shows how AI platforms can be abused to steal user data if internal isolation fails.
In this story
