Threat · curated 8 Sep 2026

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT - Check Point Research

Coverage timeline

discovered checkpoint.com primary 8 Sep 2026thehackernews.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

The ChatGPT cross-account leakage PoC shows how a hidden prompt can quietly weaponize a user's connected apps and tools to exfiltrate Gmail data, chat history, and files without any visible sign to the victim, underscoring the exfiltration risk of connected-app AI agents.

Check Point Research disclosed a proof-of-concept flaw in ChatGPT dubbed "The Shared Clipboard," where a single planted instruction — delivered via a malicious prompt, shared conversation, or custom GPT — could covertly cause a victim's ChatGPT session to execute attacker tasks while returning a normal-looking answer. In the PoC, ChatGPT read data from the victim's connected Gmail account and relayed it to a second, attacker-controlled ChatGPT account through a hidden cross-account channel that exploited a shared internal package-delivery service reachable from otherwise-isolated code-execution containers.