ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
A vulnerability in OpenAI ChatGPT has been revealed by cybersecurity experts. This vulnerability takes use of the AI assistant's implicit faith in Markdown links and images to cause prompt injections and make phishing attacks possible.
Permiso Security has given the method the code name ChatGPhish.
Markdown links and Markdown image URLs that came from a third-party page the assistant just summarized are trusted by the chatgpt.com answer renderer. According to a report provided with The Hacker News by security researcher Andi Ahmeti, it automatically retrieves such photos and displays those links as live, clickable items inside the trusted assistant user interface.
In a hypothetical attack scenario, a malicious actor could add a small payload to any webpage that the victim later a...

