ChatGPT flaw could leak emails and calendar data, claims researcher

ChatGPT flaw could leak emails and calendar data, claims researcher

A recent incident shared by developer and Oxford alumnus Eito Miyamura has brought to light a significant security vulnerability in OpenAI's ChatGPT. In a post on social media, Miyamura revealed that he was able to exploit the newly implemented Model Context Protocol (MCP) tools to gain access to sensitive user data, including emails and calendar events, simply by using the victim’s email address. OpenAI had recently introduced full support for MCP tools in ChatGPT, enabling the AI to connect to and retrieve information from various platforms like Gmail, Google Calendar, SharePoint, and Notion. While the intention behind this feature is to boost productivity by allowing ChatGPT to access data across different services, Miyamura’s demonstration raises alarming concerns about potential misuse and security breaches. The method described by Miyamura involves sending a calendar invitation that contains a "jailbreak" prompt to the target. Notably, the victim does not need to accept the invitation for the attack to succeed. When the user interacts with ChatGPT to organize their schedule, the AI reads the malicious invite and executes the attacker's commands. This could lead to the unauthorized access of private emails, which could then be transmitted to the attacker’s own address. Currently, MCP tools are only available in developer mode and require manual approval for each session. However, Miyamura cautions that users may overlook security protocols due to decision fatigue, potentially allowing unauthorized access to sensitive information. In the midst of these security concerns, OpenAI has rolled out a highly anticipated feature in ChatGPT that allows for branching conversations. Users can now explore various discussion paths without losing track of the original context, a change that came in response to user feedback for more flexible conversation management. This new functionality is available to logged-in users on the web, enhancing the overall user experience while raising questions about data security.

Sources : Mint

Published On : Sep 13, 2025, 06:05

AI
SambaNova Secures $1 Billion Funding, Eyes Market Expansion Amid Growing AI Demand

SambaNova Systems, a prominent player in AI chip development, has successfully raised $1 billion in its Series F funding...

TechCrunch | Jul 08, 2026, 07:40
SambaNova Secures $1 Billion Funding, Eyes Market Expansion Amid Growing AI Demand
Gaming
Join the Quest: Gamers Unite to Unearth Revolutionary War Treasures

In an innovative twist on mobile gaming, players are being invited to embark on a thrilling treasure hunt for lost artif...

CNN | Jul 08, 2026, 11:55
Join the Quest: Gamers Unite to Unearth Revolutionary War Treasures
AI
Amazon's Ambitious Moonraker Project: A Deep Dive into their Costly Alexa AI Upgrade

Amazon is embarking on an ambitious new project known as 'Moonraker,' aimed at enhancing the capabilities of its Alexa A...

Business Insider | Jul 08, 2026, 09:20
Amazon's Ambitious Moonraker Project: A Deep Dive into their Costly Alexa AI Upgrade
Mobile
Protect Your Privacy: Unlocking Guest Mode on Android Devices

In today's digital age, smartphones are treasure troves of personal information, housing everything from private message...

Business Today | Jul 08, 2026, 09:10
Protect Your Privacy: Unlocking Guest Mode on Android Devices
AI
The Dark Side of AI Distillation: A Threat to Industry Profits

Recent developments in AI distillation are raising alarms across the tech sector, as the practice begins to undermine th...

Business Insider | Jul 08, 2026, 09:20
The Dark Side of AI Distillation: A Threat to Industry Profits
View All News