International Edition
Latest News
Technology

ChatGPT Security Flaw Allowed Hackers to Hijack Gmail Emails

Security researchers at Check Point Research uncovered a hidden communication channel vulnerability between ChatGPT and Gmail that allowed malicious actors to compromise accounts and siphon confidential emails without detection. OpenAI subsequently patched the security flaw, but industry specialists…

ChatGPT Security Flaw Allowed Hackers to Hijack Gmail Emails

Security researchers at Check Point Research uncovered a hidden communication channel vulnerability between ChatGPT and Gmail that allowed malicious actors to compromise accounts and siphon confidential emails without detection. OpenAI subsequently patched the security flaw, but industry specialists warn that identical vulnerabilities persist across the broader generative artificial intelligence ecosystem.

How the ChatGPT-Gmail Security Flaw Operated

According to Check Point, the vulnerability relied on an exploited communication channel where attackers used manipulated prompts, shared web links, or custom GPTs to hijack a victim’s session. Once triggered, ChatGPT utilized the owner’s legitimate authorization rights to interact with Gmail, extracting sensitive data and transmitting it to the attacker while keeping the user chat interface entirely normal. Check Point Research characterized this technique as an “insider manipulated” attack, meaning no malware or stolen passwords were required because the system simply abused permissions already granted by the user.

Industry Response and Broader AI Vulnerabilities

OpenAI closed this specific security gap following the discovery, but technical experts emphasize that the underlying risk extends far beyond a single platform. Fred Streefland, Chief Information Security Officer at Check Point, stated that malicious actors can replicate these techniques against existing features and vulnerabilities in other AI applications, including Microsoft Copilot. Streefland noted that modern AI architecture possesses a level of complexity that makes security flaws virtually inevitable, observing that systems built to be intelligent are simultaneously exposed to sophisticated exploitation.

Mitigating Risks in Enterprise AI Integrations

Organizations face significant blind spots regarding how artificial intelligence agents interact with external services. Streefland warned that a lack of organizational visibility remains the primary hazard for corporate networks, necessitating immediate upgrades to identification and protection protocols. To combat these threats, Check Point recommends that security teams complete a thorough inventory of every active AI application and agent deployed across their infrastructure.

From Instagram — related to chatgpt security flaw allowed, ChatGPT Gmail vulnerability

Furthermore, security leadership advises conducting proactive vulnerability testing and specialized red teaming prior to launching operational tools. Industry experts agree that maintaining secure digital environments requires strict governance, continuous monitoring, and preemptive testing rather than reactive patching alone.

AI Security Crisis: Hackers Exploit Copilot & ChatGPT!
About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”