logo

ChatGPT blindly trusts browser content, turning the page into a payload

ID: ba84b370-0f87-5761-8402-0884867ca311

STIX ID: report--ba84b370-0f87-5761-8402-0884867ca311

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2026-05-29

Date Updated: 2026-05-30

...
...

The report describes a prompt-injection vulnerability in ChatGPT that lets attacker-controlled Markdown produce spoofed security alerts, clickable phishing links, and embedded QR codes in the assistant’s output; a researcher demonstrated proof-of-concept attacks that could pivot from browser to mobile and disclosed the issue to OpenAI, which had not confirmed remediation—recommendations include strong sandboxing and treating model-generated content as untrusted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.