The DNS Trap: How a “Hidden” Path Allowed ChatGPT to Silently Leak Your Private Data
ID: 1510d9b7-c23d-536b-a8c3-210f8f0f2165
STIX ID: report--1510d9b7-c23d-536b-a8c3-210f8f0f2165
Feed Name: securityonline.info
Threat Score
Check Point Research discovered a DNS tunneling side channel in ChatGPT's Linux-based code execution environment that allowed sensitive user data to be encoded into DNS queries and exfiltrated to an attacker-controlled server, and could also enable a remote shell into the runtime. The company demonstrated the issue via a proof-of-concept (a “personal doctor” GPT) that leaked PDF patient data; OpenAI patched the underlying issue on February 20, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
