ChatGPhish Exploits ChatGPT Summaries for Phishing

SkimNews Take
ChatGPT's summarization feature, by prioritizing user convenience through dynamic content rendering, inadvertently creates a new attack surface where the summary itself becomes the malicious payload.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Permiso Security discovered the ChatGPhish vulnerability, which exploits ChatGPT’s automatic rendering of Markdown links and images from summarized web pages.
- ChatGPT auto‑fetches images and displays Markdown links as live, clickable elements in its UI, allowing attackers to embed malicious payloads that leak IP, User‑Agent, and Referer data.
- OpenAI’s ChatGPT UI can render QR codes and spoofed system alerts from summarized pages, letting attackers trick users into scanning malicious codes or clicking phishing links.
- Microsoft Copilot was previously shown to be vulnerable to cross‑prompt injection via attacker‑controlled email content, highlighting a broader risk across AI summarization tools.
- Adversa AI reported related attack techniques (SymJack and TrustFall) targeting AI coding agents, underscoring a growing ecosystem of AI‑focused exploits.
Why it matters: Enterprises that rely on ChatGPT for web summarization lose a critical security layer, while attackers gain a stealthy phishing channel that bypasses traditional email filters and can harvest IP and device data.




