Simcha K
OpenAI designed ChatGPT's sandbox as a secure runtime with network isolation, strict timeouts, and an AI supervisor filtering commands. Extracting data seemed impossible.
In this talk, we demonstrate an attack chain shattering this sandbox. Abusing spreadsheet parsing bypasses the supervisor for persistent root execution. We then live-patch the internal Jupyter kernel, hijacking the hidden reasoning channel to execute a Reasoning Injection Attack and extract sensitive data. To exfiltrate it, we bypass isolation by weaponizing the Task Scheduler to launder URLs past web guardrails.
The attack culminates by exploiting a shared JFrog package manager. We engineered a protocol weaponizing global authentication rate limits, translating lockout timers into a half-duplex covert channel. This provides reliable exfiltration and C&C. Our chain combines file parsing abuse, Chain of Thought hijacking, privilege confusion, and rate limit DoS to orchestrate a C2 network inside ChatGPT.
Simcha K
Senior Security Researcher - Palo Alto Networks
Simcha is a Senior Security Researcher at Palo Alto Networks with over seven years of experience in vulnerability research. He discovered his first vulnerability at age 15, earning his first bug bounty, and has since uncovered security flaws in processors, embedded systems, and large-scale open-source projects. His current work focuses on AI security, exploring the intersection of LLM and software exploitation. Simcha has presented his research in the past at BSides, Nullcon, and Black Hat