Cybersecurity researchers have disclosed a zero-click flaw in OpenAI ChatGPT's Deep Research agent that could allow an attacker to leak sensitive Gmail inbox data with a single crafted email without any user action. Following responsible disclosure on June 18, 2025, the issue was addressed by OpenAI in early August. Launched by OpenAI in February 2025, Deep Research is an agentic capability built into ChatGPT that conducts multi-step research on the internet to produce detailed reports. "We crafted a new prompt that explicitly instructed the agent to use the browser.open() tool with the malicious URL," Radware said. "The agent solved not only simple CAPTCHAs but also image-based ones -- even adjusting its cursor to mimic human behavior.