ChatGPhish Flaw in ChatGPT Could Turn Web Summaries Into Phishing Lures
Generative AI tools often retrieve webpages and summarize key points for users. But when a summary interface directly renders external content, it can also import malicious elements into a trusted conversation. Cybersecurity firm Permiso Security named the technique ChatGPhish and warned that it could expose personal data and information from multiple sources.
Permiso Security recently found that ChatGPT's response renderer automatically displays Markdown links and images embedded in webpages. Attackers can plant phishing URLs or QR codes on pages submitted for summarization, causing them to appear alongside the AI-generated summary and potentially inducing users to click. Reports on the issue did not provide an exact disclosure date, number of victims or amount of losses.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.