跳到主要內容

ChatGPT漏洞評測:跨帳號隱藏通道竊讀Gmail | ChatGPT Flaw Review: Cross-Account Gmail Data Leak

By Kit 小克 | AI Tool Observer | 2026-09-09

🇹🇼 ChatGPT漏洞評測:跨帳號隱藏通道竊讀Gmail

ChatGPT本週爆出一個相當驚悚的漏洞:資安公司Check Point Research發現,只要一段藏在對話裡的惡意指令,就能讓受害者的ChatGPT帳號在使用者毫無察覺的情況下,透過「隱藏跨帳號通道」把已連接的Gmail信箱資料外洩給攻擊者的另一個ChatGPT帳號。這不是理論上的漏洞,Check Point已經實際示範三種攻擊路徑,並已通報OpenAI、確認修補完成。

什麼是ChatGPT的隱藏跨帳號通道漏洞?

簡單說,這是一種提示注入(prompt injection)攻擊:攻擊者把惡意指令藏進一段對話、一個分享連結,或一個自訂GPT的隱藏設定裡。受害者不知情地觸發後,指令會在自己的ChatGPT帳號背景執行,利用帳號本來就有連接的工具(例如Gmail連接器),把資料寫進一個攻擊者與受害者「共用」的雲端儲存空間,攻擊者再從自己的ChatGPT帳號讀出資料。整個過程受害者的對話畫面完全看不出異常。

駭客怎麼利用這個漏洞偷看你的Gmail?

Check Point Research示範了三種投遞惡意指令的方式:

  • 直接貼上惡意提示:偽裝成正常請求,誘使使用者複製貼上一段看似無害的文字
  • 分享的ChatGPT對話連結:受害者點開別人分享的對話,指令已經藏在歷史紀錄裡
  • 自訂GPT:惡意指令寫進自訂GPT的隱藏設定,使用者看不到但每次對話都會執行

一旦受害者的ChatGPT在背景執行了這段指令,只要帳號有連接Gmail等應用程式,攻擊者理論上就能透過這個隱藏通道拿到信箱內容,而且雙方帳號完全獨立、互不可見。

OpenAI修好了嗎?一般用戶該注意什麼?

好消息是,Check Point通報後OpenAI已確認關閉造成外洩的內部服務,這個特定的跨帳號通道目前已不可利用。但提示注入這類攻擊手法不會消失——只要ChatGPT連接了Gmail、Google Drive等第三方應用,類似風險就永遠存在。實務建議:

  • 不要隨意使用來路不明的自訂GPT,尤其是要求連接Email或雲端硬碟的
  • 謹慎點開別人分享的ChatGPT對話連結,尤其內容要求你「照著做」
  • 定期檢查ChatGPT設定裡的「已連接應用程式」,用不到就斷開
  • 對提示注入保持警覺——這是2026年AI Agent安全最大的破口,不只ChatGPT,所有能連接外部工具的AI助理都有同樣風險

這次事件再次證明,AI代理(agent)的便利性和安全性是一體兩面。連接的工具越多,攻擊面就越大,而使用者往往是最後一個知道的人。

好不好用,試了才知道。


🇺🇸 ChatGPT Flaw Review: Cross-Account Gmail Data Leak

ChatGPT users got an uncomfortable security wake-up call this week: Check Point Research disclosed a vulnerability that let attackers read a victim's connected Gmail data through a hidden cross-account channel — all without the victim seeing anything unusual in their chat window. The flaw wasn't theoretical: Check Point demonstrated three working attack paths, reported it to OpenAI, and confirmed the leak vector has since been shut down.

What Is ChatGPT's Hidden Cross-Account Channel?

It's a form of prompt injection: an attacker plants a hidden instruction inside a shared conversation, a pasted prompt, or a custom GPT's configuration. When a victim unknowingly triggers it, the instruction runs quietly inside their own ChatGPT session, uses whatever connected apps (like Gmail) the victim already granted access to, and writes the stolen data to a storage location shared between the victim's and attacker's separate ChatGPT accounts. The victim's visible conversation shows nothing out of the ordinary.

How Did the Gmail Data Leak Actually Work?

Check Point demonstrated three delivery methods for the malicious prompt:

  • Direct paste — a prompt disguised as an innocent request that a user copies into chat
  • Shared conversation links — the hidden instruction was already embedded when the victim opened a link someone else shared
  • Custom GPTs — the instruction was baked into a custom GPT's hidden configuration, running silently on every chat

Once triggered, if the victim's account had Gmail (or another app) connected, the attacker could pull data across the hidden channel — with both accounts staying completely isolated and invisible to each other.

Is It Fixed? What Should Users Do Now?

The good news: OpenAI confirmed the internal service responsible for the leak has been decommissioned, closing this specific channel. But prompt injection as an attack class isn't going away — any AI assistant connected to Gmail, Google Drive, or similar third-party apps carries the same underlying risk. Practical steps:

  • Avoid custom GPTs from unknown creators, especially ones requesting email or cloud storage access
  • Be cautious opening shared ChatGPT conversation links that ask you to "follow along"
  • Regularly review "Connected Apps" in ChatGPT settings and disconnect what you don't use
  • Stay alert to prompt injection generally — it's the biggest security gap for AI agents in 2026, not just ChatGPT but any assistant that can call external tools

This incident is a reminder that agent convenience and agent security are two sides of the same coin. The more tools you connect, the bigger the attack surface — and users are usually the last to find out.

好不好用,試了才知道 — the tools are only as safe as what you connect to them.

Sources / 資料來源

常見問題 FAQ

ChatGPT的Gmail外洩漏洞現在還存在嗎?

不存在了。Check Point通報後OpenAI已關閉造成外洩的內部服務,這個特定的跨帳號通道目前無法被利用。

我的ChatGPT有連接Gmail,會被駭嗎?

這次漏洞已修補,但提示注入風險仍在,建議定期檢查「已連接應用程式」設定,關閉不需要的連接。

什麼是提示注入(prompt injection)?

指攻擊者把惡意指令藏在對話、連結或自訂GPT裡,誘使AI在使用者不知情下執行未授權操作的攻擊手法。

使用別人分享的ChatGPT對話連結安全嗎?

要謹慎,尤其內容要求你「照著操作」時;惡意指令可能已藏在分享的對話紀錄裡。

Is the ChatGPT Gmail leak vulnerability still active?

No — after Check Point's report, OpenAI decommissioned the internal service responsible, closing this specific channel.

Is it safe to open shared ChatGPT conversation links?

Be cautious, especially if asked to "follow along" — hidden instructions can be embedded in shared chat history.

延伸閱讀 / Related Articles


AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends

留言

這個網誌中的熱門文章

Google Ironwood TPU v7 推理專用晶片解析:效能追平 NVIDIA、成本低 44%,AI 晶片戰爭正式開打 | Google Ironwood TPU v7 Explained: Matching NVIDIA Performance at 44% Lower Cost — The AI Chip War Heats Up

Claude Code 實測:AI 幫你寫程式到底行不行? | Claude Code Review: Can AI Really Code for You?

Cursor vs GitHub Copilot vs Claude Code:AI 程式助手大比拼 | AI Coding Assistants Compared: Cursor vs GitHub Copilot vs Claude Code