TechNewsReel
Live

Palo Alto Networks Researcher Breaks ChatGPT Sandbox Isolation

A proof-of-concept attack uses JFrog Artifactory account lockouts as a covert channel to establish command and control.

TechNewsReel Newsroom · August 6, 2026

Simcha Kosman, a senior security researcher at Palo Alto Networks, has demonstrated a sophisticated attack chain capable of establishing full command and control (C2) within ChatGPT's isolated sandbox. Presented at Black Hat USA 2026, the research proves that logical isolation in AI runtimes can be bypassed using covert communication channels.

Kosman's proof-of-concept, titled "A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox," utilized a multi-stage exploit. The chain began with a single-click vulnerability affecting Apple devices; while Windows and Android users were prompted to review URL-based commands, iPhone and Mac users saw those commands executed immediately. Once inside, Kosman used malicious code embedded within spreadsheet cells, which ChatGPT executed during processing, allowing for the creation of persistent background processes.

The Artifactory Side-Channel

To achieve cross-sandbox communication, Kosman exploited the account lockout behavior of JFrog Artifactory. By using the lockout state as a binary covert channel—where a lockout represented a '1' and a failed login represented a '0'—the researcher established a C2 link between supposedly isolated environments. This mechanism allowed the researcher to remotely read and modify files from a separate ChatGPT session, effectively breaking the privacy barrier between users.

Implications for AI Isolation

This research challenges the fundamental assumption that secure containers provide absolute isolation for AI reasoning tasks. By demonstrating that a shared backend service can be abused to leak information or transmit commands, the attack proves that side-channel communication can undermine the security of a billion-user platform. As Kosman noted, "Private chats should stay private."

Industry Response and Next Steps

Palo Alto Networks reported five distinct findings to OpenAI on March 23, including URL laundering and reasoning injection. In response, an OpenAI spokesperson stated that the research does not represent a full escape from the security sandbox or unrestricted access to other customer accounts. OpenAI further confirmed that the specific vulnerabilities used in the Black Hat proof-of-concept were addressed prior to the presentation. Security teams are now tasked with evaluating whether similar side-channel vulnerabilities exist in other cloud-based AI sandboxes.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.