ChatGPT's Trust in Web Links Opens Door for Phishing Attacks, Researchers Warn

Security researchers have uncovered a vulnerability in OpenAI's ChatGPT that could turn the popular AI assistant into a phishing tool. The flaw, dubbed ChatGPhish by Permiso Security, exploits how ChatGPT handles links and images when summarizing web pages.
When a user asks ChatGPT to summarize a third-party website, the AI's response renderer automatically fetches images from that page and displays any Markdown links as clickable elements. This trust can be abused by attackers who embed malicious code into seemingly harmless web pages.
In a typical attack scenario, a bad actor adds a small payload to a web page. When a victim later asks ChatGPT to summarize that page, the AI fetches attacker-hosted images, leaking the user's IP address, browser type, and referral data. The same technique can display fake security alerts, phishing links, or QR codes that trick users into scanning them with their phones—bypassing desktop security filters.
"The shift from email to the browser significantly expands the potential attack surface," Permiso noted. "A user no longer has to open a malicious attachment. Simply summarizing a page during normal browsing can introduce attacker-controlled instructions into the model's response."
This isn't the first time researchers have flagged risks in AI summarization. Earlier this year, Permiso showed how Microsoft Copilot could be manipulated by specially crafted emails. But ChatGPhish stands out because it doesn't require complex exploits—just a regular web page with hidden instructions.
As companies increasingly rely on ChatGPT for research and summarization, the vulnerability means any employee who asks the AI to process a malicious page could unwittingly turn it into a phishing surface. The findings add to a growing list of AI security concerns, including attacks on coding agents and email security systems.
Permiso urges organizations to review how they deploy AI tools and consider additional safeguards when using them to process external content.
Source: The Hackers News
dArt Studio installs AI for local businesses in Broward & Palm Beach County, FL. We reply within 1 business hour.