AI · 168 days ago
Check Point found a ChatGPT flaw that let a crafted prompt make the model exfiltrate conversation text and uploaded files through a DNS-based side channel in the Linux code-execution runtime. OpenAI released fixes for ChatGPT and a separate Codex GitHub token issue on February 20, 2026. Researchers say there is no evidence the flaw was exploited in the wild.
2 sources covering this story
Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise
Researchers found an OpenAI Codex vulnerability that could have been exploited to compromise GitHub tokens.
OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability
ChatGPT and Codex flaws patched Feb 2026 exposed DNS exfiltration and GitHub tokens, raising enterprise AI security risks.
Part of the PlainSec briefing for 2026-03-31