ChatGPT Deep Research Agent Exposes Gmail Data via ShadowLeak Flaw
A zero-click flaw in ChatGPT Deep Research leaks Gmail data via hidden HTML prompts, bypassing security measures.
Published: Sep 20, 2025 | Author: Ravie Lakshmanan | Category: Artificial Intelligence / Cloud Security

Cybersecurity researchers at Radware have uncovered a critical zero-click vulnerability in OpenAI ChatGPT's Deep Research agent, dubbed ShadowLeak, which allows attackers to exfiltrate sensitive Gmail inbox data with a single crafted email—requiring no user interaction.
How ShadowLeak Works
The attack exploits indirect prompt injection, where malicious instructions are hidden in email HTML (e.g., tiny fonts, white-on-white text, or CSS tricks). When the victim uses ChatGPT Deep Research to analyze their Gmail, the agent reads and executes these hidden commands, exfiltrating data to an attacker-controlled server.
- No user action needed: The flaw is triggered automatically when the agent processes the email.
- Bypasses traditional defenses: Data exfiltration occurs directly from OpenAI's cloud infrastructure, evading local or enterprise security tools.
- Broad attack surface: While demonstrated with Gmail, the flaw could affect other ChatGPT connectors like Microsoft Outlook, Dropbox, and GitHub.

Key Takeaways
- Responsible Disclosure: Radware reported the issue to OpenAI on June 18, 2025, and a patch was deployed in early August 2025.
- Unique Cloud-Based Exfiltration: Unlike client-side attacks (e.g., AgentFlayer or EchoLeak), ShadowLeak operates entirely within OpenAI's cloud, making detection harder.
- Base64 Encoding: Attackers instructed the agent to encode stolen data in Base64 before exfiltration, framing it as a "security measure."
Related News
AWS extends Bedrock AgentCore Gateway to unify MCP servers for AI agents
AWS announces expanded Amazon Bedrock AgentCore Gateway support for MCP servers, enabling centralized management of AI agent tools across organizations.
CEOs Must Prioritize AI Investment Amid Rapid Change
Forward-thinking CEOs are focusing on AI investment, agile operations, and strategic growth to navigate disruption and lead competitively.
About the Author

Dr. Sarah Chen
AI Research Expert
A seasoned AI expert with 15 years of research experience, formerly worked at Stanford AI Lab for 8 years, specializing in machine learning and natural language processing. Currently serves as technical advisor for multiple AI companies and regularly contributes AI technology analysis articles to authoritative media like MIT Technology Review.