30.1 C
Delhi
Monday, March 2, 2026

ChatGPT Flaw Let Hackers Steal Gmail Data Without Clicks

AI Security Flaw Exposed Gmail Data in Zero-Click Attack

A critical vulnerability in ChatGPT’s Deep Research tool allowed hackers to steal Gmail data without any user interaction. Dubbed “ShadowLeak,” this zero-click attack exploited hidden prompts in emails that the AI agent unknowingly executed while analyzing inbox content.

Key Takeaways

  • Hackers used invisible text in emails to hijack ChatGPT’s Deep Research tool
  • The attack stole Gmail data through OpenAI’s cloud environment, bypassing local security
  • OpenAI patched the vulnerability in August 2025 after Radware researchers discovered it
  • Similar threats could affect other AI integrations with popular platforms

How the ShadowLeak Attack Worked

Attackers embedded hidden instructions using white-on-white text or CSS tricks in seemingly harmless emails. When users asked ChatGPT to analyze their Gmail inbox, the AI agent unknowingly executed these commands.

The agent then used its built-in browser tools to exfiltrate sensitive data to external servers, all within OpenAI’s cloud environment. Unlike previous attacks that ran on user devices, ShadowLeak operated entirely in the cloud, making it invisible to antivirus and firewalls.

Hidden prompts expose how hackers silently hijacked ChatGPT’s AI agent. (Kurt “CyberGuy” Knutsson)

Why This Threat Matters

The Deep Research agent’s wide access to third-party apps like Gmail, Google Drive and Dropbox created unexpected security risks. Radware researchers revealed the attack encoded personal data in Base64 and disguised it as a “security measure.”

The real danger lies in how any AI connector could be similarly exploited if attackers hide prompts in analyzed content.

What Security Experts Say

“The user never sees the prompt. The email looks normal, but the agent follows the hidden commands without question,” the researchers explained.

In separate testing, security firm SPLX demonstrated ChatGPT agents could be tricked into solving CAPTCHAs through manipulated conversation history. Researcher Dorian Schultz noted the model even mimicked human cursor movements to bypass bot detection.

Experts warn future AI integrations could face the same hidden threat. (Kurt “CyberGuy” Knutsson)

Protection Measures Against ShadowLeak-Style Attacks

Disable Unused Integrations: Turn off any AI connections you’re not actively using, such as Gmail, Google Drive or Dropbox integrations.

Limit Personal Data Exposure: Consider data removal services to reduce your digital footprint across people-search sites and data broker databases.

Avoid Analyzing Unknown Content: Don’t ask AI tools to examine emails or documents from unverified sources where hidden prompts might lurk.

Monitor Security Updates: Enable automatic updates from OpenAI, Google, Microsoft and other platforms to receive critical patches promptly.

Use Comprehensive Antivirus: Install strong antivirus protection that can detect phishing links, hidden scripts and AI-driven exploits across all devices.

Implement Layered Security: Combine updated browsers, operating systems, endpoint protection and email filtering for comprehensive defense.

Key Security Insights

AI technology is advancing faster than security systems can adapt. Even with prompt patching, attackers continuously find new ways to exploit integrations and context memory. Maintaining vigilance and restricting AI agent permissions remains your strongest protection strategy.

The fundamental question remains: Can we trust AI assistants with sensitive personal data when they can be so easily manipulated?

Latest

Sam Altman reveals real reason why OpenAI rushed to partner with US Military after Trump banned Anthropic

OpenAI executives have given more information regarding the AI startup’s contract with the US Department of Defense after facing backlash online. The Sam Altm

After Donald Trump banned Anthropic, US Military used Claude in Iran strikes: Here is what changed

The US Military reportedly used Anthropic’s Claude AI model during its strikes on Iran. The attack on Iran came just a day after US President Donald Trump ins

SIM binding rules go live starting March 1: These WhatsApp, Telegram, Signal and other messaging app users to be impacted

Tech News News: Starting March 1, messaging apps like WhatsApp, Telegram, Signal and others must comply with the Department of Telecommunications' SIM-binding r

More than one year after DeepSeek’s R1 wiped nearly $600 billion off Nvidia market value in single day, Chinese startup planning another launch

Tech News News: DeepSeek, the Chinese AI startup that wiped nearly $600 billion off Nvidia’s market value in a single day with launch of its R1 model, is repo

Nothing Phone 4a and 4a Pro launching on 5 March: Design, expected specs and more

Nothing is set to launch its Phone 4 (a) series on 5 March. The launch event is also likely to see the unveling of new Headphone (a) with bold colors and long b

Topics

Taliban attacks Pak’s Nur Khan base in latest escalation of cross border conflict

Taliban forces reportedly launched armed drone strikes targeting Pakistan’s Command and Control Centre at Nur Khan Air Base in Rawalpindi. Taliban forces carr

Satellite images show damage across Iranian military sites after US-Israel strikes

Fresh satellite imagery shows visible damage to air, drone and naval facilities near Iran’s Konarak region amid escalating regional tensions. The visuals offe

Sensex down 1,000 points: Why is the stock market falling today?

The S&P BSE Sensex fell sharply in early trade, and the NSE Nifty50 also slipped more than 1%, as investors reacted to the fast-changing situation between the U

Qatar, UAE, Syria, Oman: Full list of places that saw attacks amid US-Iran conflict

The Middle East is engulfed in conflict as Iran retaliates against US-Israeli strikes, launching missile and drone attacks across multiple countries. 

AIIMS-trained neurologist warns against repeatedly using reheated cooking oils: ‘Risk of cancer increases manifold…’

Reusing cooking oil is a common practice in many households, but does the money it saves outweigh the health risks? Dr Sehrawat explains the health risks.

Quote of the day by Jon Bon Jovi: ‘You better stand tall when they’re calling you out, don’t bend, don’t break…’

On his birthday, we look back at one of Jon Bon Jovi's most influential quotes, which highlights the importance of standing tall in the face of criticism.

Satellite images show black smoke over Dubai as Iran continues to fire missiles, drones

Iran-US war: Dubai's skyline has dramatically changed after Iranian attacks, with smoke visible in satellite images.

Sam Altman reveals real reason why OpenAI rushed to partner with US Military after Trump banned Anthropic

OpenAI executives have given more information regarding the AI startup’s contract with the US Department of Defense after facing backlash online. The Sam Altm
spot_img

Related Articles

Popular Categories

spot_imgspot_img