← registry

ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

A vulnerability in ChatGPT allowed a hidden prompt instruction to exfiltrate a user's Gmail data to an attacker's account while the system continued responding normally to legitimate queries.

Categoryprompt_injection
Severityhigh
AI systemchatbot
Sectorstechnology
Harm typesprivacysecurity
Lifecycle stageoperation
Actorexternal_attacker
Published2026-09-08 14:19:17

Summary is Secursion's own; full text lives at the source. Attribution preserved.