logo

ChatGPhish: The Page Is the Payload

ID: 70c3b29b-5889-5bc0-b2e5-1eefed3e87bb

STIX ID: report--70c3b29b-5889-5bc0-b2e5-1eefed3e87bb

Feed Name: Cloud Chronicles

Threat Score
65/100

Date Published: 2026-05-29

Date Updated: 2026-07-29

Author: [email protected] (Andi Ahmeti)

...
...

This research demonstrates a browser-based prompt-injection vulnerability in ChatGPT’s page-summarization flow where attacker-controlled Markdown links and images from third-party web pages are passed into and rendered by the assistant as live UI; this enables phishing (clickable spoofed alerts), QR-code-based mobile pivots that bypass desktop defenses, and cross-origin information leakage (auto-fetched images/shorteners leaking IP, User-Agent, Referer, and timing). The report contains payload examples, screenshots, and a disclosure timeline showing engagement with OpenAI.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.