logo

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

ID: af1956cc-203e-5184-961a-96552285be3d

STIX ID: report--af1956cc-203e-5184-961a-96552285be3d

Feed Name: Check Point Research

Threat Score
70/100

Date Published: 2026-09-08

Date Updated: 2026-09-10

Author: stcpresearch

...
...

Check Point Research discovered a covert cross-account channel in ChatGPT where isolated code-execution containers could use an internal Artifactory storage API as a shared clipboard, enabling an attacker to deliver hidden instructions (via prompts, shared conversations, or custom GPTs) that caused a victim's session to execute secondary tasks and exfiltrate data (including connected Gmail and conversation files) to the attacker; OpenAI decommissioned the identified Artifactory instance after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.