VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_20ea1f70b7865e02249209fc79cea35a

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Published May 29, 2026

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks.

The technique has been codenamed ChatGPhish by Permiso Security.

"The chatgpt.com response renderer trusts Markdown links and Markdown

Affected AI Products

prompt injection chatgpt openai
Get the weekly digest. Every Monday: top AI security stories of the week. Free.