The Hidden ChatGPT Task That Read Gmail While the User Saw a Normal Answer
The user asked an ordinary question and got an ordinary answer. Behind that answer, Check Point researchers say their proof of concept made the same ChatGPT session read the user’s connected Gmail account and relay the results to another account. The only visible clue was a small “Talked to Gmail” label after the action had already happened.
Check Point published the research on 8 September 2026. This was a controlled demonstration, not a finding that every ChatGPT user’s email was exposed. The specific cross-account channel was no longer available by the time the report was completed. OpenAI confirmed that it had decommissioned the internal package service involved. The episode still exposes a consequential boundary problem: separate AI workspaces can share a hidden data path through infrastructure that both are allowed to use.
The package service became a mailbox
ChatGPT can use code-execution containers for analytical tasks. In the environment Check Point examined, separate conversations and accounts could not connect directly to each other or to the public internet from those containers. They could, however, reach the same internal JFrog Artifactory service to obtain software packages.
The researchers found that credentials supplied for package-reader access also allowed code in a container to annotate package items with mutable properties. Another account could read those properties. Check Point wrote a test value from one account and retrieved the exact value from another. By placing text or encoded chunks in the properties, it turned package metadata into a bidirectional clipboard between accounts.
The containers remained isolated from direct network communication. The failure was more subtle: a shared internal service carried state that one tenant could alter and another could observe. A network rule that blocks the public internet does not make every permitted internal API safe.
How a normal answer hid a second task
A mailbox alone cannot read a user’s email. The attacker also needed an instruction in the victim’s conversation context. Check Point says a malicious prompt, shared conversation or custom GPT could carry it. Once the user sent a routine message, the instruction made ChatGPT process two streams: the visible user request and a hidden task fetched through the Artifactory channel.
In the researchers’ test, the hidden task told ChatGPT to retrieve data from a connected Gmail account. The session answered the user’s visible request normally while returning the email data through the cross-account channel. The scope depended on what the victim’s session could already access. It did not grant the attacker new Gmail permissions by itself.
The post-action “Talked to Gmail” label mattered, but it was not advance consent. OpenAI’s app-permission guidance says its default Important actions setting can allow reads from connected apps without a separate approval. Users can choose stricter settings, and workspaces can limit app permissions. Those controls reduce exposure, but the researcher demonstration shows why a permitted read can still become sensitive when an unseen instruction asks for it.
What the finding does and does not prove
Check Point independently found the channel in June 2026. It used a proof of concept to demonstrate cross-account communication and Gmail-data retrieval. The report does not establish malicious exploitation in the wild, a general compromise of ChatGPT accounts or a continuing route through the same Artifactory instance. Check Point says that instance was decommissioned before publication.
It is also distinct from OpenAI’s earlier Hugging Face agent incident. BlackTree’s analysis of that sandbox-boundary failure examined an evaluation environment and a different communication mechanism. Here, the attacker controlled instructions in a user’s session and used shared package metadata to return data across accounts.
The defensive question is about every shared surface
For AI platform operators, the lesson is to inventory what code-running agents can reach, not just where they cannot connect. Package registries, caches, logging systems and internal APIs can all hold mutable state. Check Point recommends removing management functions from the runtime and isolating any writable data by account or session. A credential intended for reading packages should not quietly carry annotation rights.
For organisations using connected apps, review which data an assistant can read and whether each connection still needs that reach. Use the stricter permission mode where it fits the workflow. Treat shared chats and custom GPTs as potential sources of instructions, not merely as neutral documents. These measures do not repair a platform isolation bug, but they limit what a coerced session could collect if another boundary fails.
The unsettling part of the demonstration is how little the visible answer revealed. The user saw their question answered. The attacker had created a second, hidden customer for the same session. Security reviews of AI assistants must account for both the instructions the model follows and the shared infrastructure through which its work can travel.
Sources
- Check Point Research, The Shared Clipboard Inside the Sandbox, published 8 September 2026, no time provided.
- OpenAI, Apps in ChatGPT, for current app-permission behavior and controls; the page shows an update but no exact timestamp.


