ChatGPhish: every page your agent summarizes is now a phishing surface.
ChatGPhish: every page your agent summarizes is now a phishing surface
Permiso disclosed three working prompt-injection chains in ChatGPT's Markdown renderer on May 29, 2026: fake OpenAI security buttons, inline QR codes that pivot to mobile, and tracking pixels that leak IP and User-Agent. Why the renderer is the wrong trust boundary, and what every browse-with-LLM product just inherited.