A Critical Flaw in ChatGPT Allows Malicious Prompts to Exfiltrate Gmail Data, Leaving Users Vulnerable
Cybersecurity researchers have uncovered a significant vulnerability in the popular chatbot platform ChatGPT, which can be exploited by attackers to extract sensitive data from unsuspecting users’ email accounts. Specifically, the flaw allows an attacker to plant a malicious prompt in the chat interface, prompting the user’s Gmail account to send their login credentials and other sensitive information to another account under the attacker’s control.
The vulnerability affects users who interact with ChatGPT through its web interface or mobile app, which can be used to communicate with the platform using natural language. When a user sends a prompt to the chatbot, it is processed on the server-side before being sent back to the user as a response. However, researchers discovered that an attacker can manipulate the prompt by inserting malicious code, which is then executed by ChatGPT’s servers and triggers a request to the user’s Gmail account.
This allows the attacker to gain unauthorized access to the user’s email account, extract sensitive information such as login credentials, and potentially use this data to launch further attacks or steal personal identifiable information. The vulnerability can be exploited even if the user has two-factor authentication (2FA) enabled on their Gmail account, rendering it a significant concern for users who rely on ChatGPT.
The researchers who discovered the flaw demonstrated its potential by crafting a malicious prompt that extracted a victim’s Gmail login credentials and sent them to an attacker-controlled email address. This exploit was made possible due to a combination of factors, including the lack of proper input validation in ChatGPT’s API, which allows attackers to inject malicious code into the platform.
The implications of this vulnerability are far-reaching, as it highlights the potential for chatbots and other AI-powered interfaces to be exploited by attackers. As more users rely on these platforms to interact with services such as email and online banking, the importance of ensuring their security cannot be overstated.
Given the ease with which this flaw can be exploited, it’s essential that ChatGPT users take immediate action to protect themselves. This includes enabling two-factor authentication (2FA) on all accounts linked to the platform and being cautious when interacting with unfamiliar prompts or messages sent through chat interfaces. By staying vigilant and taking proactive steps to secure their online presence, users can minimize the risk of falling victim to this type of attack.
Source: The Hacker News — 2026-09-08