logo

OpenAI patches ChatGPT flaw that smuggled data over DNS

ID: bad37bac-4944-5849-ad13-6c887d7dc3b0

STIX ID: report--bad37bac-4944-5849-ad13-6c887d7dc3b0

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2026-03-30

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

### Executive summary Check Point researchers found a DNS-based side-channel in ChatGPT's code execution/data analysis environment that allowed a single malicious prompt to exfiltrate uploaded user data to an attacker-controlled server; proof-of-concept attacks showed sensitive information leakage and OpenAI patched the issue on 2026-02-20.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.