Check Point Research disclosed a since-fixed vulnerability in which a hidden instruction planted inside a ChatGPT conversation, shared chat, or custom GPT could make the assistant secretly read a victim’s connected Gmail data in the background while answering the visible question normally. The stolen data was passed to a second attacker-controlled ChatGPT account through a covert channel built from shared, mutable metadata on a cached package-repository item inside OpenAI’s code-execution sandboxes, effectively bridging containers that were meant to be isolated from each other. The only visible trace was a small “Talked to Gmail” label, with no prompt asking the user to allow or deny the access. OpenAI decommissioned the internal Artifactory instance involved, and the channel was no longer reachable by the time the report was published.