{"rewrite":{"id":"r_9e476c5caa9d4487be8549df","clusterId":"c_dcca671f1f3ea6ccd05f7ed9","slug":"check-point-finds-hidden-channel-between-chatgpt-accounts","model":"deepseek-v4-flash","headline":"Check Point Finds Hidden Channel Between ChatGPT Accounts","summary":"Check Point Research says it found a covert communication channel linking the code execution containers of two separate ChatGPT accounts. An internal package delivery service, meant to keep containers isolated, could be read from and written to by any container, letting one session hand tasks to another. In a live demonstration the attacker retrieved data from the victim's connected Gmail, while the victim saw only a normal reply. OpenAI has confirmed the vulnerability is fixed.","whyItMatters":"The finding turns every AI assistant holding credentials, tools, and connected apps into what Check Point calls a coerced insider, so runtime protection of legitimate access matters more than the assumption of account separation.","webCardHtml":"\u003cp\u003eThe channel ran through an internal package delivery service that ChatGPT code execution containers use to fetch software without direct internet access. Check Point Research says that service, designed to keep containers isolated, could be read from and written to by any container, so a session on one account could quietly hand tasks to a session on another.\u003c/p\u003e\u003cp\u003eThe victim received no warning. A malicious prompt from the attacker, a shared conversation link, or a custom GPT was enough. Check Point demonstrated data being pulled from a victim\u0026#39;s connected Gmail while the victim\u0026#39;s own conversation looked ordinary.\u003c/p\u003e","blueskyPost":"Check Point's finding means a container reading another session's package stream could reach connected services like Gmail; OpenAI calling it fixed does not tell users whether anything was read before the patch.","twitterPost":"Check Point reached a victim's connected Gmail from another ChatGPT session. A patch closes the channel but cannot confirm whether it was used before.","threadsPost":"Check Point showed a session pulling data from a victim's connected Gmail while the victim saw only a normal reply. OpenAI confirmed the fix, but the demonstration raises the harder question for anyone with plug-ins attached: finding the channel and knowing it was never used are different problems.","newsletterBlurb":"Check Point Research says it found a covert channel between the code execution containers of two separate ChatGPT accounts, running through an internal package delivery service that any container could read from and write to. In a live demonstration the attacker's session took data from the victim's connected Gmail, while the victim saw only an ordinary reply. OpenAI has confirmed the vulnerability is fixed.","attributionJson":"[{\"source\":\"ASCII.jp\",\"url\":\"https://ascii.jp/elem/000/004/434/4434243/?rss\",\"title\":\"Check Point Reveals Potential for Unauthorized Access to Connected Apps via Hidden Communication Channel Between ChatGPT Accounts\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4503,"outputTokens":545,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1789106376,"createdAt":"2026-09-11T05:55:02.000Z","publishedAt":"2026-09-11T05:58:23.000Z","updatedAt":"2026-09-11T05:58:23.000Z"},"cluster":{"id":"c_dcca671f1f3ea6ccd05f7ed9","canonicalTitle":"チェック・ポイント、ChatGPTのアカウント間に潜む隠れた通信経路を経由した連携アプリへの不正アクセスにつながる可能性を明らかに","representativeArticleId":"a_8ad120d6671ecb20bc2948d7","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[\"ChatGPT\"],\"studios\":[\"Check Point\"],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-09-11T03:00:09.000Z","lastSeenAt":"2026-09-11T03:00:09.000Z","updatedAt":"2026-09-11T05:58:20.000Z"},"attribution":[{"source":"ASCII.jp","url":"https://ascii.jp/elem/000/004/434/4434243/?rss","title":"チェック・ポイント、ChatGPTのアカウント間に潜む隠れた通信経路を経由した連携アプリへの不正アクセスにつながる可能性を明らかに"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":["ChatGPT"],"studios":["Check Point"],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
