
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Researchers discovered a vulnerability in ChatGPT's code-execution environment that allowed attackers to execute hidden tasks in other users' sessions, exfiltrating sensitive data such as Gmail emails without user awareness. The flaw exploited a shared internal Artifactory service, violating user privacy before OpenAI decommissioned the affected infrastructure.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (ChatGPT's AI agents) whose malfunction (a security flaw in container isolation and metadata sharing) directly led to unauthorized access and theft of sensitive personal data (Gmail messages and other connected services). This constitutes a violation of privacy rights and harm to property (data). The harm has occurred, not just a potential risk, and the AI system's architecture and use are central to the incident. Although the specific vulnerability has been patched, the incident itself is a realized AI Incident. The warning about similar risks in other platforms is complementary information but does not negate the classification of this event as an AI Incident.[AI generated]