ChatGPT side‑channel could leak conversations; OpenAI patched

Check Point found a ChatGPT flaw that let a crafted prompt make the model exfiltrate conversation text and uploaded files through a DNS-based side channel in the Linux code-execution runtime. OpenAI released fixes for ChatGPT and a separate Codex GitHub token issue on February 20, 2026. Researchers say there is no evidence the flaw was exploited in the wild.

Part of the PlainSec briefing for 2026-03-31

Sources