Key Takeaways:
- Attack requires only a user’s email address to hijack a ChatGPT account.
- Exploit extends to Microsoft Copilot Studio, Salesforce Einstein, and linked Google Drive files.
- Vulnerability could allow delivery of malware or misleading AI-generated advice.
- OpenAI and Microsoft have issued fixes, though some providers characterized it as expected system behavior.
- Highlights growing security risks as AI tools become deeply integrated into enterprise workflows.
At Black Hat 2025, Zenity CTO Michael Bargury revealed a “zero-click” vulnerability in ChatGPT that allowed attackers to take over accounts using only the victim’s email address. Once exploited, the attacker could access all chat history and any files linked through Google Drive. This access could be used to insert malicious instructions, distribute harmful content, or manipulate advice provided by the AI, according to Ynet News.
Zenity’s research showed that the vulnerability was not limited to ChatGPT. Similar security flaws were found in Microsoft Copilot Studio and Salesforce Einstein, exposing a broader issue in AI platform security. The potential damage is amplified by the integration of these tools into corporate environments, where access often extends to sensitive or proprietary data.
OpenAI and Microsoft moved quickly to address the issue, releasing patches soon after disclosure. However, some providers reportedly dismissed the exploit as normal system behavior rather than a vulnerability, raising concerns about how seriously certain AI vendors treat emerging threats.
The demonstration underscores the need for more robust security measures as AI becomes central to business operations. As enterprises adopt AI-driven tools for critical workflows, protecting these systems from sophisticated, account-level exploits will be vital to preventing large-scale data breaches and manipulation campaigns.
Learn how AI Agents can supercharge your company’s profits and productivity at TMC’s AI Agent Event in Sept 29-30, 2025 in DC.
Rich Tehrani serves as CEO of TMC and chairman of ITEXPO #TECHSUPERSHOW Feb 10-12, 2026 and is CEO of RT Advisors and is a Registered Representative (investment banker) with and offering securities through Four Points Capital Partners LLC (Four Points) (Member FINRA/SIPC). He handles capital/debt raises as well as M&A. RT Advisors is not owned by Four Points.
The above is not an endorsement or recommendation to buy/sell any security or sector mentioned. No companies mentioned above are current or past clients of RT Advisors.
The views and opinions expressed above are those of the participants. While believed to be reliable, the information has not been independently verified for accuracy. Any broad, general statements made herein are provided for context only and should not be construed as exhaustive or universally applicable.
Portions of this article may have been developed with the assistance of artificial intelligence, which may have contributed to ideation, content generation, factual review, or editing.






