logo

ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime

ID: 2f8de235-a074-5b2a-a7a0-7887f2b8008e

STIX ID: report--2f8de235-a074-5b2a-a7a0-7887f2b8008e

Feed Name: Check Point Research

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-27

Author: alexeybu

...
...

Check Point Research disclosed a vulnerability in ChatGPT’s isolated code-execution/runtime environment that could be triggered by a single malicious prompt or backdoored GPT to silently exfiltrate user messages and uploaded files via DNS tunneling and to create a bidirectional channel enabling remote shell access; multiple PoCs demonstrated data theft of sensitive content and remote command execution, and OpenAI confirmed and fully deployed a fix on 2026-02-20.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.