logo

ChatGPT Security Issue Enabled Data Theft via Single Prompt

ID: fcc4cfcd-8a20-544e-97d0-2f55b39108bf

STIX ID: report--fcc4cfcd-8a20-544e-97d0-2f55b39108bf

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

...
...

A Check Point report details a ChatGPT vulnerability in which a single malicious prompt could activate a hidden DNS-based exfiltration channel from the model's isolated execution container, enabling leakage of user messages, uploaded files, and other sensitive content; researchers demonstrated the issue with a proof-of-concept PDF and reported the issue to OpenAI, which deployed a fix on February 20, while noting it is unknown if the bug was exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.