New ChatGPT Flaws Allow Attackers to Exfiltrate Sensitive Data from Gmail, Outlook, and GitHub
Recent vulnerabilities in ChatGPT have been identified that allow unauthorized access to sensitive data from integrated services such as Gmail, Outlook, and GitHub, without the need for user interaction.
Recent vulnerabilities in ChatGPT have been identified that allow unauthorized access to sensitive data from integrated services such as Gmail, Outlook, and GitHub, without the need for user interaction.
The vulnerabilities, named ShadowLeak and ZombieAgent, exploit ChatGPT's Connectors and Memory features to facilitate zero-click attacks, persistence, and propagation.
OpenAI's Connectors allow ChatGPT to integrate seamlessly with external systems including Gmail, Jira, GitHub, Teams, and Google Drive. The Memory feature, which is enabled by default, stores user interactions to personalize responses, enabling the AI to access or modify user data.
While these features enhance functionality, they also expose personal and corporate data to potential risks due to inadequate security measures.
ChatGPT Zero-Click and One-Click Attacks
Attackers can send malicious emails or share files containing hidden instructions, which may be masked using white text, tiny fonts, or footers.
In zero-click server-side attacks, ChatGPT processes email contents during regular operations such as email summarization, executing the payload, and leaking data via OpenAI's servers before detection by users.
One-click attacks occur when users upload compromised files, leading to chained attacks on connected repositories or drives.
OpenAI's Connectors allow ChatGPT to integrate seamlessly with external systems including Gmail, Jira, GitHub, Teams, and Google Drive.
Attack Type Trigger Exfiltration Method Scope
Zero-Click Server-Side Shared a malicious file Via browser.open() tool on OpenAI servers Gmail inboxes, PII
One-Click Server-Side Memory modification via a file Hidden prompts in docs Google Drive, GitHub
Persistence (ZombieAgent) Memory modification via file Ongoing leaks per query All chats, medical data
Propagation Email address harvesting Auto-forward to contacts [query context] Organizational spread
Although OpenAI has blocked dynamic URL modifications, researchers bypassed these protections using pre-built URLs for each character. This technique exfiltrates data without detection by client-side security measures, browsers, or user interfaces.
For persistence, attackers can inject memory-altering rules through files, which enables data leakage with each message interaction.
Despite restrictions on the combination of Connectors and Memory features, reverse access methods continue to allow extensive data exfiltration, even in new conversations. Propagation techniques involve scanning inboxes for email addresses and automatically sending payloads, targeting organizational networks.
The issues were reported by Radware on Tue, Sep 26, 2025, through BugCrowd, with details and upgrade suggestions provided. OpenAI addressed the ShadowLeak vulnerability on Wed, Sep 3, 2025, and resolved all reported issues by Tue, Dec 16, 2025, after thorough testing.
Industry experts recommend close monitoring of agent behaviors and input sanitation to mitigate risks associated with AI blind spots.
Based on reporting by Cyber Security News.
