ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
A vulnerability, dubbed ChatGPhish, has been discovered in OpenAI’s ChatGPT that allows attackers to leverage the AI’s summarization feature to create phishing attacks. By appending malicious content to a webpage, attackers can trick ChatGPT into rendering clickable links, fake security alerts, and QR codes within the AI’s response, expanding the attack surface beyond traditional email-based phishing. This highlights the potential for summarization tools to become adversarial surfaces for malicious actors.
The vulnerability, detailed by Permiso Security, centers around ChatGPT’s trust in Markdown links and images fetched from third-party pages. When a user prompts ChatGPT to summarize a webpage containing attacker-controlled images, the AI automatically renders those images and links within its response. This allows an attacker to embed malicious content, such as a QR code leading to a phishing site, directly within the trusted AI interface. The attack leverages the AI’s tendency to trust information presented within its response, effectively turning any malicious webpage into a potential phishing surface. This represents a shift in attack vectors, moving away from traditional email attachments and suspicious messages to a more subtle approach – simply summarizing a page with ChatGPT.
