A worrying ChatGPT bug let strangers read Gmail messages via a hidden cross-account channel
Researchers say it's worth an investigation, in spite of caveats
by https://www.techradar.com/author/sead-fadilpai · TechRadarNews By Sead Fadilpašić Published 9 September 2026
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
- Check Point Research exposed coerced insider flaw in ChatGPT’s agent architecture
- Containers shared metadata via internal service, enabling cross‑account prompt injection and data theft
- OpenAI closed the path, but CPR warns similar risks may exist in other AI platforms
ChatGPT’s AI agents were allowed to pull sensitive data from one account shared with an entirely different account because, colloquially speaking, all agents used to walk down the same hallways, experts have warned.
A new report from security experts Check Point Research (CPR) dubbed the flaw “coerced insider”, since it revolves around persuading the agent instead of abusing a vulnerability.
Coerced insider
When an AI agent is given a task that needs code execution, it handles that task in an isolated container which also sometimes needs to install software. To enable that, without giving containers direct internet access (which would be too risky), OpenAI routes those packages through an internal JFrog Artifactory instance. As a separate security contingency, containers from different accounts cannot talk between themselves.
Latest Videos FromTechRadarWatch full video here:
However - they can reach the same internal service (our proverbial hallways), which exposes an item management feature that lets the containers attach text or binary properties to a repository item. As a result, any container can read back the properties written by any other container.
“Check Point Research confirmed the isolation gap directly: a property written from one account’s container was fully readable from a different account’s container moments later, with data too large for one property simply split into chunks and reassembled on the other end,” the researchers explained.
“The package delivery metadata effectively became a shared clipboard between containers that were supposed to be walled off from one another.”
From there, the exploit turns into your usual, off-the-shelf prompt injection. The only difference is that the malicious prompt is not delivered directly to the victim, but rather left in the hallways, and the results are not shared with the attackers directly, but rather left in those same proverbial hallways, too.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors