ChatGPT Vulnerability Let Attackers Silently Exfiltrate User Prompts and Other Sensitive Data
ID: 854d11f2-fb2b-5e70-bb25-87cc079e1e19
STIX ID: report--854d11f2-fb2b-5e70-bb25-87cc079e1e19
Feed Name: cybersecurityNews.com
Threat Score
## Executive Summary Check Point Research disclosed a vulnerability in ChatGPT's isolated code execution environment that allowed attackers to use DNS tunneling to silently exfiltrate sensitive user data (chat history, uploaded files, AI outputs) and to receive encoded commands back into the runtime, effectively enabling a stealthy remote shell; the issue was patched on 2026-02-20.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
