HomeUpdatesOpenAI fixes data extraction vulnerability in ChatGPT

OpenAI fixes data extraction vulnerability in ChatGPT

A vulnerability in OpenAI's ChatGPT allowed sensitive chat without the user's knowledge or consent, according to new findings from Check Point.

OpenAI ChatGPT

“A malicious prompt could turn an otherwise ordinary conversation into a hidden export channel, leaking user messages, uploaded files , and other sensitive content,” the cybersecurity firm said. “A backdoored GPT could exploit the same vulnerability to gain access to user data without the user’s awareness or consent.”

After responsible disclosure, OpenAI addressed the issue on February 20, 2026. There is no evidence that the issue was actually used in an attack.

See also: Fortinet Forticlient EMS: Critical vulnerability used in attacks

While ChatGPT is built with various safeguards to prevent unauthorized data sharing or the creation of direct outbound network requests, the newly discovered vulnerability bypasses these safeguards by exploiting a side channel originating from the Linux runtime used by the AI ​​agent for code execution and data analysis.

How does the ChatGPT vulnerability work?

Specifically, the vulnerability exploits a hidden DNS-based communication path as a “hidden transport mechanism.” It does this by encoding information in DNS requests to bypass the AI’s visible security controls. The same hidden communication path could be used to establish access shell within the Linux runtime and execute commands. In the absence of any warning or user authorization dialog, the vulnerability creates a security blind spot, with the AI ​​system assuming that the environment was isolated.

OpenAI fixes data extraction vulnerability in ChatGPT

An example could involve an attacker who could convince a user to paste a malicious prompt by presenting it as a way to unlock premium features for free or improve ChatGPT performance.

The threat increases when the technique is embedded in custom GPTs, as the malicious logic could be embedded there, rather than tricking the user into pasting a specially crafted prompt.

See also: Citrix NetScaler: Vulnerability used in reconnaissance activities

“Because the model operated on the assumption that this environment could not directly send data externally, it did not recognize this behavior as an external data transfer requiring resistance or user intervention,” Check Point explained. “As a result, the leak did not trigger warnings about data leaving the conversation, did not require explicit user confirmation, and remained largely invisible.”

With tools like ChatGPT increasingly integrated into enterprise environments and users uploading highly personal information, vulnerabilities like the one above highlight the need to implement extra security measures.

“ This research reinforces a harsh truth about the AI ​​era: don’t assume AI tools are secure by default ,” Eli Smadja , head of research at Check Point Research, told The Hacker News . “ As AI platforms evolve into full computing environments that handle our most sensitive data, native security controls are no longer sufficient on their own. Organizations need independent visibility and layered protection between themselves and AI vendors. That’s how we move forward with security – by redesigning the security architecture for AI, not reacting to the next incident .”

OpenAI fixes data extraction vulnerability in ChatGPT

The development comes as malicious actors have been observed releasing extensions web browser (or updating existing ones) that engage in the dubious practice of prompt stealing to silently siphon AI chatbot conversations without the user’s consent. Therefore, seemingly harmless add-ons could become a conduit for data extraction.

See also: Smart Slider 3 WordPress: Vulnerability affects thousands of sites

“It almost goes without saying that these plugins open the door to a number of risks, including identity theft, targeted phishing campaigns, and the theft of sensitive data that is offered for sale on underground forums,” said Expel researcher Ben Nahorney. “In the case of organizations where employees may have unwittingly installed these extensions, they may have exposed intellectual property.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS