ChatGPT Sandbox Flaw Enables Cross-Account Data Theft via Covert Channel
September 8, 2026
oecd:2026-09-08-9c96View source ↗
What happened
Researchers discovered a vulnerability in ChatGPT's code-execution environment that allowed attackers to execute hidden tasks in other users' sessions, exfiltrating sensitive data such as Gmail emails without user awareness. The flaw exploited a shared internal Artifactory service, violating user privacy before OpenAI decommissioned the affected infrastructure.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
OECD AI Incidents Monitor
ChatGPT Sandbox Flaw Enables Cross-Account Data Theft via Covert Channel
2026-09-08