Researcher Claims Control of ChatGPT Secure Sandbox
ID: 1020e353-e968-5df1-92e3-52dfe4ec7356
STIX ID: report--1020e353-e968-5df1-92e3-52dfe4ec7356
Feed Name: Dark Reading
A Palo Alto Networks researcher demonstrated at Black Hat 2026 a proof-of-concept attack that bypassed ChatGPT's sandboxing and LLM supervision: URL-initiated prompt execution on macOS/iPhone, malicious spreadsheet cell code execution, reasoning-injection into the model's hidden Python environment, and a covert cross-tenant C2 channel using JFrog Artifactory account lockout behavior to encode bits. The researcher reported five findings to OpenAI, which removed or mitigated several of the behaviors within a 90-day disclosure window, and OpenAI stated the research did not represent an escape to unrestricted cross-account access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
