ChatGPhish: The Page Is the Payload
ID: 70c3b29b-5889-5bc0-b2e5-1eefed3e87bb
STIX ID: report--70c3b29b-5889-5bc0-b2e5-1eefed3e87bb
Feed Name: Cloud Chronicles
This research demonstrates a browser-based prompt-injection vulnerability in ChatGPT’s page-summarization flow where attacker-controlled Markdown links and images from third-party web pages are passed into and rendered by the assistant as live UI; this enables phishing (clickable spoofed alerts), QR-code-based mobile pivots that bypass desktop defenses, and cross-origin information leakage (auto-fetched images/shorteners leaking IP, User-Agent, Referer, and timing). The report contains payload examples, screenshots, and a disclosure timeline showing engagement with OpenAI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
