logo

The DNS Trap: How a “Hidden” Path Allowed ChatGPT to Silently Leak Your Private Data

ID: 1510d9b7-c23d-536b-a8c3-210f8f0f2165

STIX ID: report--1510d9b7-c23d-536b-a8c3-210f8f0f2165

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Check Point Research discovered a DNS tunneling side channel in ChatGPT's Linux-based code execution environment that allowed sensitive user data to be encoded into DNS queries and exfiltrated to an attacker-controlled server, and could also enable a remote shell into the runtime. The company demonstrated the issue via a proof-of-concept (a “personal doctor” GPT) that leaked PDF patient data; OpenAI patched the underlying issue on February 20, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.