跳转到主要内容

ChatGPT's ShadowLeak Vulnerability Exposed Gmail Data Theft

ChatGPT's ShadowLeak Vulnerability: A Stealthy Gmail Data Theft

Security researchers have uncovered a critical vulnerability in ChatGPT's 'Deep Research' mode, enabling attackers to silently extract sensitive data from users' Gmail accounts. Dubbed 'ShadowLeak,' this flaw exploited OpenAI's own cloud infrastructure, making it nearly undetectable by traditional security measures.

How the Attack Worked

The attack began with a carefully disguised email containing hidden HTML instructions. These directives tricked ChatGPT's Deep Research agent into extracting personal data—such as names and addresses—from other emails in the user's inbox. The stolen information was then encoded using Base64 and sent to an external server controlled by the attacker.

Image

Key to the attack's success was social engineering. Attackers manipulated the agent into believing it had authorization to perform the task, often citing urgent reasons like "incomplete reports." When users initiated a Deep Research query (e.g., "analyze my HR emails today"), the agent unknowingly executed malicious commands without alerting the user.

The Root Cause: Tool Execution Flaws

Radware researchers clarified that the vulnerability did not stem from ChatGPT's language model itself, but rather from its ability to execute tools. Specifically, an internal function called browser.open() allowed the agent to initiate HTTP requests, creating an entry point for exploitation.

Broader Implications Beyond Email

The researchers warned that this attack method isn't limited to Gmail. Any platform processing structured text—such as Google Drive, Outlook, Teams, or GitHub—could be at risk. Malicious instructions could hide in meeting invites, shared PDFs, or chat logs, turning routine AI tasks into security liabilities.

OpenAI's Response and Fixes

Radware reported the issue to OpenAI via Bugcrowd on June 18, 2025. By early August, OpenAI had implemented a fix but only publicly acknowledged resolving the problem on September 3rd.

The Persistent Threat of Prompt Injection

The incident underscores the fragility of AI agent systems, particularly against Prompt Injection attacks. These exploits embed hidden commands in seemingly benign text, bypassing user awareness. Despite years of awareness, no foolproof solution exists. Studies indicate nearly all internet-connected AI agents are vulnerable to manipulation leading to data leaks or malware downloads.

Even OpenAI CEO Sam Altman has cautioned against delegating high-risk tasks to AI agents.

Key Points:

  • ShadowLeak exploited ChatGPT’s Deep Research mode to steal Gmail data silently.
  • Attackers used social engineering and hidden HTML instructions to bypass safeguards.
  • The flaw lay in tool execution capabilities (browser.open() function), not the language model itself.
  • Risks extend beyond email to platforms like Google Drive and GitHub.
  • OpenAI patched the vulnerability after a delayed public acknowledgment.

喜欢这篇文章?

订阅我们的 Newsletter,获取最新 AI 资讯、产品评测和项目推荐,每周精选直达邮箱。

每周精选完全免费随时退订

相关文章

News

ChatGPT Agent深陷定位危机,四分之三用户流失

OpenAI旗下ChatGPT Agent在发布仅六个月后遭遇惊人用户流失,周活跃用户数从400万暴跌至不足100万,流失率达75%。产品定位混乱——甚至其名称也误导了用户对其功能的认知——加上性能问题,共同导致了这场失望风暴。随着OpenAI转向开发专用代理,这为拥挤的AI市场中明确产品差异化提供了警示案例。

January 30, 2026
ChatGPTAI产品用户留存
News

ChatGPT以60美元高价CPM推出广告,押注高购买意向

OpenAI正以大胆的定价策略在ChatGPT上推出广告——每千次展示收费60美元,是Meta平均费率的三倍。这一高价反映了ChatGPT的独特优势:用户通常带有明确的购买意图,使广告更加有效。令人意外的是,OpenAI采取了隐私优先的策略,向广告商提供最少的数据,同时自动屏蔽未成年人的广告。此举可能重新定义AI平台如何在盈利与用户信任之间取得平衡。

January 27, 2026
AI广告ChatGPT数字营销
News

ChatGPT取代谷歌成为默认浏览器选择,抢尽风头

人们在线获取信息的方式正在发生惊人转变。新数据显示,全球72%的ChatGPT订阅用户已将其设为浏览器默认主页,绕过了谷歌等传统搜索引擎。此举威胁到谷歌长期以来的主导地位,或将重塑整个数字格局。随着科技巨头争相适应变革,用户正用浏览器投票——选择对话式AI而非经典搜索框。

January 27, 2026
ChatGPTGoogleSearchEngines
OpenAI豪赌广告业务:60美元CPM对标NFL级别野心
News

OpenAI豪赌广告业务:60美元CPM对标NFL级别野心

OpenAI以每千次展示60美元的高价推出ChatGPT广告,价格是Meta的三倍,正在颠覆数字广告行业。这家AI巨头瞄准旅行推荐等高价值查询场景,计划将其海量用户转化为110亿美元的收入流。尽管目前数据能力落后于谷歌和Meta,但行业观察家认为这与Facebook早期的广告增长轨迹相似。

January 27, 2026
OpenAI数字广告ChatGPT
News

ChatGPT广告定价堪比超级碗时段

OpenAI新推出的ChatGPT广告平台以其高端定价策略引发关注。每千次展示收费60美元的费率堪比黄金时段超级碗广告。该公司放弃了传统的点击付费模式而选择按展示付费,这源于对用户与AI聊天机器人交互方式差异的认知。尽管CEO萨姆·奥特曼曾称广告'反乌托邦',但商业现实似乎已改变了OpenAI的立场。

January 27, 2026
ChatGPT数字广告OpenAI
News

ChatGPT对就业影响的真相:用工下滑早于AI热潮

最新研究颠覆普遍认知:科技领域的就业市场低迷其实在ChatGPT问世前数月就已开始。经济学家通过分析数百万领英档案和劳动力数据发现,计算机科学领域的失业风险在2022年初达到顶峰——而在ChatGPT推出后反而放缓。这些发现挑战了关于AI对劳动力即时影响的假设,指出美联储加息和疫情调整等更广泛的经济因素才是主因。

January 26, 2026
ChatGPT就业市场AI影响