ChatGPT flaw could leak emails and calendar data, claims researcher

ChatGPT flaw could leak emails and calendar data, claims researcher

A recent incident shared by developer and Oxford alumnus Eito Miyamura has brought to light a significant security vulnerability in OpenAI's ChatGPT. In a post on social media, Miyamura revealed that he was able to exploit the newly implemented Model Context Protocol (MCP) tools to gain access to sensitive user data, including emails and calendar events, simply by using the victim’s email address. OpenAI had recently introduced full support for MCP tools in ChatGPT, enabling the AI to connect to and retrieve information from various platforms like Gmail, Google Calendar, SharePoint, and Notion. While the intention behind this feature is to boost productivity by allowing ChatGPT to access data across different services, Miyamura’s demonstration raises alarming concerns about potential misuse and security breaches. The method described by Miyamura involves sending a calendar invitation that contains a "jailbreak" prompt to the target. Notably, the victim does not need to accept the invitation for the attack to succeed. When the user interacts with ChatGPT to organize their schedule, the AI reads the malicious invite and executes the attacker's commands. This could lead to the unauthorized access of private emails, which could then be transmitted to the attacker’s own address. Currently, MCP tools are only available in developer mode and require manual approval for each session. However, Miyamura cautions that users may overlook security protocols due to decision fatigue, potentially allowing unauthorized access to sensitive information. In the midst of these security concerns, OpenAI has rolled out a highly anticipated feature in ChatGPT that allows for branching conversations. Users can now explore various discussion paths without losing track of the original context, a change that came in response to user feedback for more flexible conversation management. This new functionality is available to logged-in users on the web, enhancing the overall user experience while raising questions about data security.

Sources : Mint

Published On : Sep 13, 2025, 06:05

Social Media
TikTok Faces Backlash Over Alleged Censorship of Anti-ICE Content Amid Technical Issues

TikTok has found itself at the center of controversy as users report difficulties uploading videos critical of the Immig...

CNN | Jan 27, 2026, 03:05
TikTok Faces Backlash Over Alleged Censorship of Anti-ICE Content Amid Technical Issues
AI
Nvidia Unveils Revolutionary AI Models for Swift Weather Forecasting

In a groundbreaking advancement for meteorological technology, Nvidia has introduced a new collection of open-source art...

Business Today | Jan 27, 2026, 06:55
Nvidia Unveils Revolutionary AI Models for Swift Weather Forecasting
Gadgets
Apple Unveils Next-Gen AirTag with Enhanced Features and Connectivity

Apple has officially launched an upgraded version of its AirTag, introducing significant enhancements after nearly five ...

Business Today | Jan 27, 2026, 06:00
Apple Unveils Next-Gen AirTag with Enhanced Features and Connectivity
AI
Nvidia Faces Challenges with Bank of America’s AI Implementation: A Race Against Time

Nvidia is encountering significant hurdles as it partners with Bank of America to implement its advanced AI enterprise s...

Business Insider | Jan 27, 2026, 10:00
Nvidia Faces Challenges with Bank of America’s AI Implementation: A Race Against Time
Startups
From Crisis to Triumph: The Resurgence of Tata Elxsi Under S Devarajan

In the early 1990s, Tata Elxsi was on the verge of collapse when S Devarajan took the helm. The company faced severe fin...

Business Today | Jan 27, 2026, 07:05
From Crisis to Triumph: The Resurgence of Tata Elxsi Under S Devarajan
View All News