ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel

A covert cross-account communication channel inside ChatGPT let an attacker hijack a victim’s session and silently exfiltrate data from connected apps like Gmail, all while the victim saw nothing unusual in their conversation. The vulnerability exploited ChatGPT’s code-execution containers, isolated sandboxes the assistant uses when a task requires running code or installing software packages. These […]

This article has been indexed from Cyber Security News

Read the original article: