Scams & Phishing News Browser Extensions Can Exploit ChatGPT, Gemini in ‘Man in the Prompt’ Attack

Brownie2019

Level 23
Thread author
Verified
Under Review
Well-known
Forum Veteran
Mar 9, 2019
962
2,630
2,168
Germany
A new cyberattack method, dubbed Man in the Prompt, has been identified, allowing malicious actors to exploit common browser extensions to inject harmful instructions into leading generative AI tools like ChatGPT, Google Gemini, and others. This critical finding comes from a recent threat intelligence report by cybersecurity research firm LayerX.

According to researchers, it all starts with how most AI tools function within web browsers. Their prompt input fields are part of the web page’s structure (known as the Document Object Model, or DOM). This means that virtually any browser extension with basic scripting access to the DOM can read or alter what users type into AI prompts, even without requiring special permissions.
Read more: