BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ShadowLeak Attack Exposes Gmail Data via ChatGPT ‘Deep Research’ Flaw

ShadowLeak: Critical ChatGPT Flaw Allowed Gmail Data Theft via Email-Based AI Prompt Injection

  • Researchers found a security flaw in OpenAI ChatGPT’s Deep Research tool that leaks Gmail inbox data through a single crafted email.
  • The attack, called ShadowLeak, requires no user interaction and was fixed by OpenAI in August 2025.
  • The method uses hidden commands in email formatting to trick the AI agent into exfiltrating data from cloud services.
  • This vulnerability bypasses standard security and works with several connectors, including Gmail, Dropbox, and Microsoft Outlook.
  • Researchers also showed how attackers can trick ChatGPT agents into solving CAPTCHAs using context manipulation.

Researchers have reported a major security vulnerability in OpenAI’s ChatGPT Deep Research agent that allowed attackers to steal Gmail inbox data using a specially crafted email. The flaw, named ShadowLeak by Cybersecurity firm Radware, involved no user action and was resolved by OpenAI in August 2025 after its disclosure in June.

- Advertisement -

The attack works through an indirect prompt injection, where malicious instructions are concealed within the email’s HTML content using methods like white-on-white text or layout tricks. These instructions remain invisible to the user but are still processed and followed by the AI agent when reading emails. Radware researchers explained, “The attack utilizes an indirect prompt injection that can be hidden in email HTML…so the user never notices the commands, but the agent still reads and obeys them.”

Unlike early methods that used images to carry out data theft, ShadowLeak enables data to be leaked directly from OpenAI’s cloud infrastructure. As described by researchers Zvika Babo, Gabi Nakibly, and Maor Uziel, this makes the breach hard to detect with typical local or enterprise security systems. The malicious email prompts the agent to scan the user’s email for sensitive information, encode it in Base64, and then send it to an external server using a browser tool.

The proof-of-concept required users to have the Gmail integration enabled in ChatGPT. However, Radware stated that the same technique can target other supported connectors such as Box, Dropbox, GitHub, Google Drive, HubSpot, Microsoft Outlook, Notion, or SharePoint, increasing the potential risk. The main difference between ShadowLeak and previous attacks is that this one operates in the cloud environment, making it less visible to conventional defenses.

In a separate demonstration, AI security platform SPLX showed that prompt manipulation can also make ChatGPT agents solve image-based CAPTCHAs, which are designed to block automated access. By framing CAPTCHAs as “fake” and continuing a conversation that established context, researchers found, “Attackers could reframe real controls as ‘fake’ to bypass them, underscoring the need for context integrity, memory hygiene, and continuous red teaming.”

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

“GothFerrari” Gets Over 6 Years for $250M Crypto Heist

Marlon "GothFerrari" Ferro was sentenced to 78 months in prison for his role in...

NEAR Devs: Blockchains Must Plan for Post-Quantum Fraud

Quantum computers could potentially crack blockchain cryptography, threatening wallet security.Near Protocol researchers argue protocols...

Critical Flaws Found in vm2 Node.js Sandbox Library

vm2 Node.js library users must urgently update to version 3.11.2 to patch twelve critical...

US Bitcoin Reserve & Crypto Law Clarity Weeks Away

White House advisor Patrick Witt says the CLARITY Act could pass by July 4,...

Musk Claims He’ll End Up Paying Trillions In Taxes

Elon Musk claims a combined 45% federal and state tax rate applies when he...

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading