➀ Eito Miyamura and his team demonstrated how ChatGPT can be tricked into revealing sensitive email data using a vulnerability in the Model Context Protocol (MCP);
➁ The vulnerability allows attackers to send a calendar invite with a jailbreak prompt to the victim's email address;
➂ ChatGPT is then manipulated to read the email and send sensitive information back to the attackers without the need for the invite to be accepted.