ChatGPT Flaw Let Hackers Steal Gmail Data Without Clicks

AI Security Flaw Exposed Gmail Data in Zero-Click Attack

A critical vulnerability in ChatGPT’s Deep Research tool allowed hackers to steal Gmail data without any user interaction. Dubbed “ShadowLeak,” this zero-click attack exploited hidden prompts in emails that the AI agent unknowingly executed while analyzing inbox content.

Key Takeaways

  • Hackers used invisible text in emails to hijack ChatGPT’s Deep Research tool
  • The attack stole Gmail data through OpenAI’s cloud environment, bypassing local security
  • OpenAI patched the vulnerability in August 2025 after Radware researchers discovered it
  • Similar threats could affect other AI integrations with popular platforms

How the ShadowLeak Attack Worked

Attackers embedded hidden instructions using white-on-white text or CSS tricks in seemingly harmless emails. When users asked ChatGPT to analyze their Gmail inbox, the AI agent unknowingly executed these commands.

The agent then used its built-in browser tools to exfiltrate sensitive data to external servers, all within OpenAI’s cloud environment. Unlike previous attacks that ran on user devices, ShadowLeak operated entirely in the cloud, making it invisible to antivirus and firewalls.

Hidden prompts expose how hackers silently hijacked ChatGPT’s AI agent. (Kurt “CyberGuy” Knutsson)

Why This Threat Matters

The Deep Research agent’s wide access to third-party apps like Gmail, Google Drive and Dropbox created unexpected security risks. Radware researchers revealed the attack encoded personal data in Base64 and disguised it as a “security measure.”

The real danger lies in how any AI connector could be similarly exploited if attackers hide prompts in analyzed content.

What Security Experts Say

“The user never sees the prompt. The email looks normal, but the agent follows the hidden commands without question,” the researchers explained.

In separate testing, security firm SPLX demonstrated ChatGPT agents could be tricked into solving CAPTCHAs through manipulated conversation history. Researcher Dorian Schultz noted the model even mimicked human cursor movements to bypass bot detection.

Experts warn future AI integrations could face the same hidden threat. (Kurt “CyberGuy” Knutsson)

Protection Measures Against ShadowLeak-Style Attacks

Disable Unused Integrations: Turn off any AI connections you’re not actively using, such as Gmail, Google Drive or Dropbox integrations.

Limit Personal Data Exposure: Consider data removal services to reduce your digital footprint across people-search sites and data broker databases.

Avoid Analyzing Unknown Content: Don’t ask AI tools to examine emails or documents from unverified sources where hidden prompts might lurk.

Monitor Security Updates: Enable automatic updates from OpenAI, Google, Microsoft and other platforms to receive critical patches promptly.

Use Comprehensive Antivirus: Install strong antivirus protection that can detect phishing links, hidden scripts and AI-driven exploits across all devices.

Implement Layered Security: Combine updated browsers, operating systems, endpoint protection and email filtering for comprehensive defense.

Key Security Insights

AI technology is advancing faster than security systems can adapt. Even with prompt patching, attackers continuously find new ways to exploit integrations and context memory. Maintaining vigilance and restricting AI agent permissions remains your strongest protection strategy.

The fundamental question remains: Can we trust AI assistants with sensitive personal data when they can be so easily manipulated?

Latest

Former Meta contractor Sama to lay off more than 1,000 workers in Kenya

Former Meta contractor Sama to lay off more than 1,000 workers in Kenya

AI is a gold mine for spammers and scammers, but Google is using it as a tool to fight back

AI is a gold mine for spammers and scammers, but Google is using it as a tool to fight back

OpenAI policy chief slams AI doomers, says we need to have more responsible conversations

OpenAI’s David Lehane urges responsible discussions around AI, highlighting risks of extreme narratives and stressing the need for balanced public understandi

AI startup Cluely hiring engineer, says it will offer free home, food and even a partner in 1 year

San Francisco-based AI startup Cluely offers a unique job package including free housing, food, and a guaranteed partner after one year.

WhatsApp may soon introduce business chat filtering to reduce spam

WhatsApp reportedly working on a new feature to reduce spam and clutter. The purported feature will help users organise business messages and keep personal chat

Topics

Markets open flat as geopolitical tensions ease, but caution remains

The BSE Sensex was trading at 78,030.99, up 42.31 points or 0.05% at around 9:43 am. The Nifty 50, however, slipped marginally by 6.85 points or 0.03% to 24,189

Kerala SSLC Results in May, plus two on May 25, confirms education minister

Kerala SSLC and Plus Two Result 2026 dates have been officially announced, giving students clarity on when to expect their scores. The state has also rolled out

Who is Girija Ji? PM Modi meets veteran educationist after 30 years, praises her work

Prime Minister Narendra Modi’s Nagercoil visit blended politics and personal warmth as he reunited with veteran educationist Gomatam Veeraraghavan Girija afte

Lebanon ceasefire: Who said what? Bibi vows troops will stay; Trump hails talks ‘very exciting’ – How Iran reacts?

Iranian Parliament speaker Ghalibaf asserts that Lebanon must be included in any peace agreement between Iran and the U.S., emphasizing its importance for regio

‘Targeting of commercial shipping unacceptable,’ India calls restoration of safe navigation in Strait of Hormuz at UN

India's Ambassador Harish P raised concerns at the UN over threats to commercial shipping in the Strait of Hormuz, urging for safe navigation and calling for de

All-round Arshdeep Singh: Viral reels spiking Punjab Kings’ fanbase, says pacer

Arshdeep Singh took some credit for the spike in Punjab Kings' fan base, saying that his social media game is one of the reasons behind the increase in follower

Pope Leo after clash with Trump over Iran war, says world ‘ravaged by a handful of tyrants’

The remarks come as the pontiff continues an 11-day visit to Africa, using his platform to advocate for peace and international cooperation.

New York loses nearly $74 million for not revoking 33,000 illegal licenses for immigrant truckers

New York loses nearly $74 million for not revoking 33,000 illegal licenses for immigrant truckers
spot_img

Related Articles

Popular Categories

spot_imgspot_img