You can prompt-inject ChatGPT by asking it to summarise a web page for you. Andi Ahmeti from Permiso got ChatGPT to display his chosen phishing link or QR code in ChatGPT’s own output to the user — so an evil link looks like it’s a system message from ChatGPT itself. [Permiso] How do you do […]