Executive Summary
In June 2025, a critical zero-click vulnerability, codenamed ShadowLeak, was discovered in OpenAI ChatGPT’s Deep Research agent. This flaw enabled attackers to exfiltrate sensitive Gmail inbox content merely by sending a specially crafted email to victims using the agent, requiring no user action. Security researchers from Radware, after identifying the issue, disclosed it responsibly to OpenAI, which released a fix in early August 2025. The flaw had the potential to compromise confidential data across enterprise and personal Gmail accounts, raising major concerns around AI-driven integrations and email ecosystem security.
This breach highlights the accelerating convergence of artificial intelligence with traditional email attack surfaces, raising unique risks around invisible, automated threat vectors. With GenAI agents increasingly embedded into communication flows, attackers are rapidly adapting zero-click tactics to exploit new behaviors and trust assumptions.
Why This Matters Now
AI-powered research agents are now being integrated into email and productivity platforms at scale. The ShadowLeak incident exposes how these tools can introduce novel, hard-to-detect attack routes that bypass user awareness and existing defenses. Immediate action is needed to reassess AI agent security, especially for zero-click exploits.
Attack Path Analysis
The attacker initiated the compromise by exploiting a zero-click vulnerability in the ChatGPT Deep Research agent, triggering the flaw through a crafted email to gain unauthorized access to Gmail inbox data. Privilege escalation occurred as the malicious input manipulated internal agent permissions, bypassing logical access controls. The attacker moved laterally within cloud environments by interacting with interconnected services or gaining access to adjacent Gmail or cloud assets. Command and control was maintained via the Deep Research agent, which was leveraged to orchestrate covert actions and maintain communications. Sensitive data was exfiltrated as Gmail inbox contents were transmitted to an external adversary-controlled endpoint, using trusted service channels to evade detection. The impact resulted in exposure of confidential email data and a breach of user privacy, with potential regulatory and reputational consequences.
Kill Chain Progression
Initial Compromise
Description
An attacker delivered a crafted email to the ChatGPT Deep Research agent, exploiting a zero-click flaw that enabled the agent to trigger information disclosure without user interaction.
Related CVEs
CVE-2025-XXXX
CVSS 9A zero-click vulnerability in OpenAI's ChatGPT Deep Research agent allows attackers to exfiltrate sensitive Gmail inbox data via crafted emails without user interaction.
Affected Products:
OpenAI ChatGPT Deep Research Agent – prior to August 2025
Exploit Status:
exploited in the wildReferences:
MITRE ATT&CK® Techniques
Malicious File
Phishing: Spearphishing Attachment
Web Protocols
Data from Local System
Automated Exfiltration
JavaScript
Data from Information Repositories
Indirect Command Execution
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of Public-Facing Applications
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT System Security Requirements
Control ID: Art. 8(2)
CISA Zero Trust Maturity Model 2.0 – Zero Trust for Applications and Workloads
Control ID: Identity & Device Pillars: Protect Email and Application Interfaces
NIS2 Directive – Incident Handling and ICT Security
Control ID: Art. 21(2)(e)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
ShadowLeak AI security flaw poses critical risk to sensitive financial communications through Gmail, requiring enhanced egress security and threat detection capabilities.
Health Care / Life Sciences
Zero-click Gmail data exfiltration via ChatGPT Deep Research threatens HIPAA compliance, demanding strengthened email security and AI governance frameworks.
Legal Services
Attorney-client privileged communications vulnerable to AI-powered Gmail data leaks, necessitating immediate email encryption and zero trust segmentation implementation.
Information Technology/IT
IT sector faces heightened AI security risks from ShadowLeak attacks, requiring comprehensive visibility controls and anomaly detection for GenAI integrations.
Sources
- ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research Agenthttps://thehackernews.com/2025/09/shadowleak-zero-click-flaw-leaks-gmail.htmlVerified
- ChatGPT Deep Research zero-click vulnerability fixed by OpenAIhttps://www.malwarebytes.com/blog/news/2025/09/chatgpt-deep-research-zero-click-vulnerability-fixed-by-openaiVerified
- Zero-Click Flaw in ChatGPT's Agent Enables Silent Gmail Data Thefthttps://www.infosecurity-magazine.com/news/vulnerability-chatgpt-agent-gmail/Verified
- OpenAI Fixed ChatGPT Security Flaw That Put Gmail Data at Riskhttps://www.bloomberg.com/news/articles/2025-09-18/openai-fixed-chatgpt-security-flaw-that-put-gmail-data-at-riskVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, workload isolation, and egress policy enforcement would have detected, constrained, or blocked attacker actions by limiting agent permissions, controlling cloud-to-cloud interactions, and preventing unauthorized outbound data flows.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline enforcement would detect abnormal AI agent activation and block malicious payloads at ingress.
Control: Zero Trust Segmentation
Mitigation: Least privilege policies restrict internal access, minimizing blast radius even if logic is bypassed.
Control: East-West Traffic Security
Mitigation: Lateral movement detection and policy enforcement prevents unauthorized workload-to-workload communications.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous agent behaviors generate alerts and can trigger automated incident response.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound attempts to unauthorized destinations are blocked, preventing data loss.
Centralized observability ensures rapid incident detection and compliance reporting.
Impact at a Glance
Affected Business Functions
- Email Communications
- Data Analysis
- Research Operations
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive Gmail inbox data, including personally identifiable information (PII) and confidential business communications.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation for AI/agentic cloud workloads to restrict privilege escalation and lateral movement.
- • Apply granular egress filtering and FQDN-based controls to prevent unauthorized data exfiltration from SaaS and cloud agents.
- • Implement distributed real-time threat detection to baseline and monitor AI agent behavior for anomalous or exploit-triggered actions.
- • Leverage centralized, cross-cloud traffic visibility to quickly detect, contain, and investigate cross-service attacks.
- • Regularly validate and update cloud-native service permissions, ensuring least privilege and removing unused access paths for all automation agents.



