Summary
Check Point Research uncovered a critical bug in ChatGPT's agent architecture that allowed strangers to read Gmail messages via a hidden cross-account channel. The flaw, dubbed "coerced insider," enabled prompt injection and data theft by exploiting shared metadata between isolated containers, though OpenAI has since closed this specific vulnerability.