→ Back to Home
AI Security

ChatGPT Vulnerability: Phishing Attacks Exploit AI Page Summarization Feature

A novel and concerning security vulnerability has been identified in ChatGPT's widely used web page summarization capability, illustrating a new vector for sophisticated phishing attacks. Andi Ahmeti, a threat hunter at the security firm Permiso, demonstrated how a specially crafted web page could be used to trick ChatGPT into producing a summary that contains a deceptive security alert, complete with a malicious link redirecting users to an attacker-controlled website. This method is particularly insidious because it exploits the user's trust in the AI assistant itself; victims are not clicking on suspicious external links but rather on content generated within their seemingly secure ChatGPT conversation. The vulnerability is categorized as a prompt injection attack, a known challenge in the AI security landscape. Prompt injection involves embedding malicious instructions within data that the AI model processes, causing it to execute unintended commands as if they were legitimate. While prompt injection is not entirely new, Permiso's demonstration is notable for its simplicity and effectiveness, requiring no initial suspicious click from the user and abusing a function—page summarization—that users typically perceive as harmless. This incident highlights a critical flaw: ChatGPT, in this scenario, struggles to differentiate between its own generated output and external malicious content, making it susceptible to manipulation. This discovery arrives amidst increasing scrutiny of the security of AI assistants that can browse the web. For instance, OpenAI's own ChatGPT Atlas, launched in October 2025 with a built-in agent, has faced criticism for its security posture. Tests conducted by security firm LayerX revealed a high failure rate against real phishing attacks, with Atlas allowing 97 out of 103 attempts to pass, significantly underperforming traditional browsers like Microsoft Edge and Google Chrome. OpenAI has acknowledged the persistent challenge of prompt injection, stating in a December 2025 post that it is unlikely to be fully solved, and that agent modes inherently expand the attack surface. In response, OpenAI has implemented countermeasures, including an automated attack system trained adversarially to identify new exploitation techniques, alongside confirmation prompts before sensitive actions like sending messages or making payments. However, the Permiso discovery underscores that the battle against AI-driven vulnerabilities is ongoing. Experts advise users to exercise the same level of caution with links and alerts within ChatGPT conversations as they would with unexpected emails. The rise of AI-generated malware and the expanding capabilities of AI models mean that the attack surface will continue to grow, necessitating constant vigilance and evolving security practices for both developers and users of AI tools.
#chatgpt#ai security#phishing#prompt injection#vulnerability#cybersecurity
Read original source