AIWAS
ServicesPricingKnowledge BaseBlogGet Started
Email Us At
Get Started
Home » Alerts & Business  »  ChatGPT connected apps: a planted message read a user’s Gmail
Check Point planted an instruction in a ChatGPT conversation and it quietly read the user's connected Gmail. Here is how the instruction got in, what the user saw, and the one permission setting to change.

ChatGPT connected apps: a planted message read a user’s Gmail

A security firm hid an instruction inside a ChatGPT conversation. The person using that conversation asked an ordinary question and got an ordinary answer. Nothing looked wrong. In the background, ChatGPT opened that person's connected Gmail account, read what was there, and passed it to someone else's ChatGPT account.

This is not a story about an AI deciding to steal your email. It is a story about a tool that was told what to do by a stranger, and did it, because the instruction arrived in the one place the tool treats as trustworthy: the conversation in front of it.

What Check Point actually found

The research comes from Check Point, a security company, published on September 8, 2026 in a report called The Shared Clipboard Inside the Sandbox.

Some background in one paragraph. When ChatGPT needs to run code — to crunch a spreadsheet, make a chart, convert a file — it does that inside a sealed workspace that belongs only to your account. The whole point of that workspace is that it cannot see anyone else's. Check Point found that every one of these sealed workspaces could reach the same internal storage service, and that the service let them write and read small notes without ever checking which account the note belonged to. The researchers' own description is the clearest one: it worked like "a shared clipboard between isolated containers."

Two accounts that were supposed to be walled off from each other could now leave messages for each other. That is the whole flaw. Everything that follows is just what you can do with a mailbox nobody is watching.

What Check Point did with it was run a demonstration. They planted an instruction in a victim's conversation. The victim then typed something completely unrelated — in the write-up, a cooking question. ChatGPT answered the cooking question. It also checked the hidden mailbox, found a task left there by the attacker, carried that task out using the victim's own connected Gmail, and dropped the results back into the hidden mailbox for the attacker's account to collect.

Check Point's own summary of the effect: "The victim could receive a normal answer to their visible request while the attacker's task was processed separately."

The three ways the instruction got in

None of these involve malware, a stolen password, or a flaw in your own computer. Check Point lists three delivery routes, and all three are things people do every day:

  • A prompt the user pastes in. A block of text copied from a website, a newsletter, a forum post, or a colleague — the kind of "here's a great prompt for writing job descriptions" text that circulates constantly.
  • A shared ChatGPT conversation the user opens. Someone sends you a link to a chat. The instruction is already sitting in the history when you start typing.
  • A custom GPT. These are prebuilt assistants anyone can publish. The instruction lives in the builder configuration behind the assistant — text the person using it is never shown.

Look at that list from a business owner's seat. Every one of those three is an ordinary act of convenience performed by a helpful employee trying to get work done faster. There is no moment in any of them that feels like a security decision.

The only thing the user would have seen

This is the part worth sitting with. According to Check Point, the single visible sign that anything extra happened was a small "Talked to Gmail" label in the response.

That is the same label you see when you ask ChatGPT to look at your email on purpose. There was no warning, no permission box, no red flag. Just a small gray line that most people have been trained to read as "the assistant is doing its job."

Why this matters if you have connected anything to ChatGPT

The reach of an attack like this is not decided by the attacker. It is decided by what the person already connected.

Check Point notes that a task running this way could use whatever the victim's session could use — the chat history, uploaded files, and any connected service, such as email, file storage, or workplace chat. If your assistant is connected to the mailbox where your invoices, bank correspondence, supplier contracts, and password reset emails live, that is the size of the exposure. Not because the AI is untrustworthy, but because you gave a tool a key and someone else learned how to ask that tool to use it.

There is a second detail here that outlives this specific flaw, and it is the one to act on. OpenAI's own documentation, as reported by The Hacker News, sets the default permission level for connected apps to "Important actions" — a setting that allows ChatGPT to read from a connected app without prompting you. Reading is treated as low risk, so it is not something you get asked about. A user who wants to be asked every time can switch the setting to "Always ask."

Most people have never opened that setting. It is doing exactly what it was designed to do, quietly, every day.

What to do this week

None of this needs a security team or a budget. It is about twenty minutes of settings and one conversation with your staff.

  • Look at what is actually connected. Open ChatGPT's settings and find the connectors or connected apps list. Most people are surprised by what is on it. Disconnect anything you are not actively using — you can always reconnect it.
  • Switch the permission to "Always ask." This is the single highest-value change in this article. It turns a silent read into a question you have to answer, which means a hidden instruction cannot quietly help itself.
  • Do not connect the account that holds the most. If the owner's mailbox is where the banking, legal, and payroll mail arrives, that is the worst possible account to attach to a general-purpose assistant. Use a narrower account for AI work.
  • Treat shared chat links and custom GPTs like attachments from a stranger. A link to someone else's conversation is content you did not write, going into a tool that acts on content. Same for a custom GPT from an unknown publisher — you cannot read its hidden instructions.
  • Give your team one plain rule. Something like: nobody connects a company account to an AI tool without asking first. That rule costs nothing and removes most of this risk before it starts.
  • Notice the tool labels. If a response mentions talking to your email or files when you did not ask it to, that is worth a second look and a mention to whoever handles your IT.

What this is not

Three honest limits, because they change how much you should worry.

There is nothing to install. Check Point disclosed the flaw to OpenAI, and OpenAI took the internal service behind the hidden channel offline. The channel no longer works. There is no update for users to apply, and no action needed to close this particular hole.

Nobody has said this was used against real people. Neither Check Point nor The Hacker News reports any evidence that an attacker used this against real users before it was closed. It was found by researchers and demonstrated by researchers. Anyone telling you your email was read has not read the same sources.

The AI did not decide to do this. It followed an instruction that a person planted. That distinction matters, because it tells you where the defense lives: not in trusting the model more or less, but in controlling what the model is allowed to reach and what text you let into its context.

The pattern underneath

Specific flaws get fixed. This one already was. The shape of the problem does not get fixed, because it is not a bug — it is how these tools work.

An AI assistant cannot reliably tell the difference between instructions from you and instructions that happen to be sitting in the text it is reading. Give that assistant keys to your email, your files, your calendar, and your company chat, and you have built something enormously useful that also does what it is told by whoever gets text in front of it.

The useful part is real, and the answer is not to stop using these tools. The answer is the boring one: connect less, ask to be asked, and know which accounts are attached to what. A tool that has to check with you before reading your mail is a tool that a planted instruction cannot use quietly.


We break down AI and security news for business owners — plain language, no jargon. More explainers in the AIWAS knowledge base, and short briefings on X at @AIWASai.

Primary source: Check Point Research — The Shared Clipboard Inside the Sandbox, September 8, 2026. Secondary: The Hacker News.

Leave a Reply

Your email address will not be published. Required fields are marked *