Home TechnologyOpenAI patches ChatGPT flaw that smuggled data ove...
Technology⭐ Featured

OpenAI patches ChatGPT flaw that smuggled data over DNS

Check Point says outbound controls blocked web traffic but overlooked DNS OpenAI talks up data security for its AI services, yet Check Point says that ChatGPT allowed data to leak through a DNS side channel before the flaw was fixed.…

6 April 2026 at 06:17 pm
1 views
OpenAI patches ChatGPT flaw that smuggled data over DNS

OpenAI recently patched a flaw in its ChatGPT service that allowed sensitive user data to be leaked through a DNS side channel. The vulnerability was discovered by cybersecurity firm Check Point, which highlighted that while OpenAI emphasizes the security of its AI services, the initial outbound controls in place only blocked web traffic and overlooked DNS requests.

The issue arose because ChatGPT, despite its claims of robust data protection, inadvertently exposed user information through DNS leaks. DNS (Domain Name System) is a critical component of internet communication, translating domain names into IP addresses. However, when not properly secured, DNS queries can inadvertently reveal sensitive data, such as user input or search history.

Check Point's findings revealed that prior to the patch, ChatGPT's DNS configuration was not adequately configured to prevent leaks. This meant that even though outbound web traffic was blocked, the DNS queries generated by the AI could still be intercepted, potentially exposing user data. The flaw was identified as a side channel attack, where data is leaked not through the primary communication channel but through ancillary information, such as DNS requests.

OpenAI responded swiftly to the discovery, issuing a patch to address the vulnerability. In a statement, OpenAI emphasized its commitment to data security and transparency, acknowledging the oversight. The company stated that it had since strengthened its DNS configuration to prevent such leaks, ensuring that user data remains protected.

This incident underscores the ongoing challenges in securing AI services, particularly those that handle large volumes of user data. While advancements in AI have brought significant benefits, they also introduce new attack vectors that must be carefully managed. The DNS side channel attack on ChatGPT highlights the need for comprehensive security measures that go beyond basic web traffic controls, encompassing all aspects of data transmission.

The patching of this flaw by OpenAI is a positive step towards enhancing the security posture of its AI services. However, it also serves as a reminder that cybersecurity is an ongoing process that requires continuous vigilance and adaptation. As AI technologies evolve, so too must the security measures in place to safeguard user data and maintain trust in these services.

In the aftermath of this discovery, users of ChatGPT may wonder about the extent of their data exposure. While OpenAI has not disclosed specific details about the extent of the leak, the company has assured users that the vulnerability has been addressed and that no data was harvested or misused. It is crucial for users to remain vigilant about the services they use and to ensure that their data is protected through robust security practices.

This incident also raises questions about the transparency of AI companies regarding their security measures. While OpenAI has been relatively open about addressing the flaw, it is unclear whether similar vulnerabilities exist in other AI services. The cybersecurity community is likely to scrutinize other AI platforms more closely in the future, pushing them to adopt stricter security protocols and to be more transparent about their vulnerabilities.

In conclusion, the DNS side channel flaw in ChatGPT serves as a cautionary tale about the importance of comprehensive security in AI services. While OpenAI has patched the vulnerability, the incident highlights the need for continuous improvement in data protection measures. As AI technologies continue to integrate into our daily lives, it is essential that companies prioritize robust security practices to protect user data and maintain public trust.

📰 Related News
Ekaya Banaras Founder Palak Shah’s ₹40 Lakh Billboard Mistake Became a Masterclass in Startup Marketing
Ekaya Banaras Founder Palak Shah’s ₹40 Lakh Billboard Mistake Became a Masterclass in Startup Marketing
Ekaya Banaras founder Palak Shah recently opened up about one of the most expensive mistakes she made while building her luxury textile brand. During the early years of the company, Shah rented a premium billboard near Delhi’s DLF Emporio to increase brand visibility. However, after forgetting to cancel the campaign, the hoarding reportedly continued running for months — resulting in losses of nearly ₹40 lakh. The incident has now become a viral example of how small operational oversights can turn into costly business lessons for startups and entrepreneurs.
28 May
Betting On AI: Jensen Huang And NVIDIA’s Rise To The Top
Betting On AI: Jensen Huang And NVIDIA’s Rise To The Top
Before AI was inevitable, it was a gamble—and Jensen Huang went all in.
14 Apr
Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1 bring confidential computing to bare metal and AI workloads
Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1 bring confidential computing to bare metal and AI workloads
Red Hat is excited to announce the release of Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1, marking a major leap forward in our confidential computing journey. These releases graduate confidential containers on bare metal from …
14 Apr
Large AI firms hoovering maximum funding, not enough for smaller startups: Y Combinator’s Ankit Gupta
Large AI firms hoovering maximum funding, not enough for smaller startups: Y Combinator’s Ankit Gupta
YC Startup School: India’s talent pool across colleges and universities are key for building next-gen startups, which is what YC is looking to tap into. It wants to target entrepreneurs building for global markets, focussed on fintech, consumer, B2B, and ecom…
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC-RESULTS/ (PREVIEW, PIX):PREVIEW-TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
Any profit result ‌above T$505.7 billion would mark the company's highest-ever quarterly net income ​and its ninth consecutive quarter of profit growth
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
On Thursday, ​TSMC is expected to report a net profit of $17.1 billion for the quarter, according to an LSEG SmartEstimate compiled from 19 analysts. The war in the Middle East threatens to disrupt the supply of production materials for semiconductors such as…
14 Apr
If we can’t kick the habit, how do we manage AI’s energy needs?
If we can’t kick the habit, how do we manage AI’s energy needs?
One can only hope that OpenAI’s Sam Altman was joking when he sought to justify the immense energy consumption of artificial intelligence
14 Apr
What caused Nvidia Blackwell GPU prices to spike? #tech
What caused Nvidia Blackwell GPU prices to spike? #tech
Blackwell GPU hourly “rent” surges on agentic AI demand A compute pricing index tracking hourly costs for Nvidia Blackwell GPUs shows a sharp climb: hourly rental hit $4.08 , up 48% from $2.75 just two months earlier. The reported driver is rising demand tied…
14 Apr
Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access
Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access
Anthropic has introduced Claude Mythos Preview, its most advanced AI model, improving significantly in reasoning, coding, and cybersecurity. Unlike previous releases, it will not be publicly available. Access is limited to a consortium of tech companies throu…
14 Apr