OpenAI emphasizes that ChatGPTs code execution environment cannot make outbound network connections. Check Point Research showed that this was not true -- at least not entirely.
The DNS Side Channel
The vulnerability used the Domain Name System (DNS) as a hidden exfiltration channel. While OpenAI blocked outbound HTTP traffic, there was no control over DNS requests. A single malicious prompt could bypass the protections and send data to an external server.
The insidious part: ChatGPT itself did not recognize the behavior as data transmission. When asked whether data had been uploaded, the model responded that the file was only stored in a secure internal location.
Proof of Concept
Check Point demonstrated the attack using a "GPT" (a third-party app built on ChatGPT) that functioned as a personal health analyst. A user uploaded a PDF with lab results and personal data. The app analyzed the data correctly -- and simultaneously transmitted it to an attacker-controlled server without the user or the model noticing.
Implications
For regulated industries (healthcare, finance), such vulnerabilities are critical. An AI service that silently leaks patient data or financial data can trigger GDPR violations, HIPAA breaches, or regulatory consequences.
OpenAI patched the vulnerability in February 2026. Details on the fix were not published.
Sources: Check Point Research Blog (30.03.2026), The Register.