OpenAI Artifactory vulnerability exposed covert data-stealing channel
Researchers disclosed a vulnerability in OpenAI's Artifactory that allowed unauthorized accounts to send hidden tasks—such as retrieving email data from connected Gmail accounts—through ChatGPT's internal system as of September 8–9, 2026. The flaw was exploited alongside a concurrent Hugging Face zero-day attack.