Mark RadarMARK RADAR
EN

ChatGPhish Flaw in ChatGPT Could Turn Web Summaries Into Phishing Lures

1 reports · First detected 2026-06-02 · Last active 2026-06-02

Generative AI tools often retrieve webpages and summarize key points for users. But when a summary interface directly renders external content, it can also import malicious elements into a trusted conversation. Cybersecurity firm Permiso Security named the technique ChatGPhish and warned that it could expose personal data and information from multiple sources.

Permiso Security recently found that ChatGPT's response renderer automatically displays Markdown links and images embedded in webpages. Attackers can plant phishing URLs or QR codes on pages submitted for summarization, causing them to appear alongside the AI-generated summary and potentially inducing users to click. Reports on the issue did not provide an exact disclosure date, number of victims or amount of losses.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR