Covert channel could let attackers use ChatGPT to execute hidden tasks

 

Covert channel could let attackers use ChatGPT to execute hidden tasks

Check Point Research has discovered a security issue that could allow attackers to use a victim’s ChatGPT session to carry out hidden tasks using the victim’s data, tools and connected apps.

In a proof of concept, researchers used the method to access email data from a victim’s connected Gmail account and send the information back to an attacker. The victim could still receive a normal answer to their question without seeing the hidden activity.

The attack worked through code-execution environments linked to different ChatGPT accounts. The environments could not directly communicate with each other or access the public internet, but they could connect to the same internal software package service. Researchers found that the service could be used to store and retrieve hidden data between accounts.

The hidden instructions could be introduced through a malicious prompt, a shared ChatGPT conversation or a custom GPT. Once the instruction was part of the conversation, a normal user message could trigger the hidden task.

Researchers said the attack could also be used to access conversation history and files available to the victim’s session. The possible damage depended on the apps, tools, data and permissions already connected to the victim’s ChatGPT account.

Check Point researchers said that by the time they completed the report, the channel was no longer available and that OpenAI confirmed that the identified internal Artifactory instance had been deactivated.


Back to the list