ChatGPT vulnerability enables malicious AI agents through phishing links

A flaw in OpenAI's platform lets attackers embed autonomous AI agents into corporate environments through social engineering, creating persistent access with employee credentials.

Abstract illustration of trusted pathways fragmenting into shadowy divergent forms
AI-generated illustration · Sylvaris

Phishing attack vector

Security researchers identified a method to embed malicious AI agents within ChatGPT links that appear legitimate. When employees click these links and authenticate with corporate credentials, the rogue agent gains persistent access to company systems through the employee's OpenAI session.

The attack leverages ChatGPT's custom GPT functionality, which allows users to create specialized AI assistants. Attackers craft agents designed to exfiltrate data, gather intelligence, or maintain surveillance while operating within the permissions of the compromised employee account.

Corporate infiltration risk

Organizations that have integrated ChatGPT or other OpenAI tools into their workflows face particular exposure. The malicious agent operates with the same access level as the employee who clicked the link, potentially reaching internal documents, code repositories, and communication channels.

Unlike traditional malware that security tools can detect and quarantine, these AI agents function as legitimate ChatGPT sessions. They can maintain access over extended periods while adapting their behavior to avoid detection, mimicking normal employee usage patterns.

OpenAI response pending

Researchers disclosed the vulnerability to OpenAI following standard responsible disclosure practices. The company has not yet issued a public statement or released patches addressing the agent-embedding mechanism.

The vulnerability highlights security challenges unique to AI platforms where the boundary between legitimate automation and malicious activity becomes difficult to establish. Traditional security controls designed for software applications may not effectively detect or prevent AI agent-based intrusions.

sources
more in Security
CISA expands Iran-linked threat alert beyond Rockwell to broader industrial control systems Federal agency widens scope of Iranian reconnaissance targeting US critical infrastructure beyond single vendor, indicating broader campaign against internet-facing industrial devices. RefluXFS Linux kernel vulnerability enables root privilege escalation through nine-year-old race condition A race condition in the XFS filesystem, present in the Linux kernel for nine years, allows local attackers to overwrite protected files and gain root access. msaRAT malware routes command traffic through Chrome and Edge browsers Chaos ransomware operators are hiding malicious command traffic by routing it through legitimate browser processes, complicating detection.