Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

ChatGPT Vulnerability Lets Attackers Embed Malicious SVGs & Images in Shared Chats

Posted on May 20, 2025May 20, 2025 By CWS

A vital safety vulnerability in ChatGPT has been found that enables attackers to embed malicious SVG (Scalable Vector Graphics) and picture recordsdata immediately into shared conversations, doubtlessly exposing customers to stylish phishing assaults and dangerous content material.

The flaw, lately documented as CVE-2025-43714, impacts the ChatGPT system by means of March 30, 2025.

Safety researchers recognized that as an alternative of rendering SVG code as textual content inside code blocks, ChatGPT inappropriately executes these parts when a chat is reopened or shared by means of public hyperlinks.

This habits successfully creates a saved cross-site scripting (XSS) vulnerability inside the widespread AI platform.

“The ChatGPT system by means of 2025-03-30 performs inline rendering of SVG paperwork as an alternative of, for instance, rendering them as textual content inside a code block, which allows HTML injection inside most trendy graphical net browsers,” stated the researcher with deal with zer0dac.

The safety implications are important. Attackers can craft misleading messages embedded inside SVG code that seem reputable to unsuspecting customers.

Extra regarding are the potential impacts on person wellbeing, as malicious actors may create SVGs with epileptic-inducing flashing results that will hurt photosensitive people.

The vulnerability works as a result of SVG recordsdata, in contrast to common picture codecs equivalent to JPG or PNG, are XML-based vector pictures that may embody HTML script tags, a reputable function of the format, however harmful when improperly dealt with.

When these SVGs are rendered inline fairly than as code, the embedded markup executes inside the person’s browser.

“SVG recordsdata can comprise embedded JavaScript code that executes when the picture is rendered in a browser. This creates an XSS vulnerability the place malicious code may be executed within the context of different customers’ classes,” explains the same vulnerability report from a unique platform.

OpenAI has reportedly taken preliminary mitigation steps by disabling the link-sharing function after the vulnerability was reported, although a complete repair addressing the underlying problem continues to be pending.

Safety specialists advocate that customers train warning when viewing shared ChatGPT conversations from unknown sources.

The vulnerability is especially regarding as a result of most customers implicitly belief content material from ChatGPT and wouldn’t count on visible manipulation or phishing makes an attempt by means of the platform.

“Even with out JavaScript execution capabilities, visible and psychological manipulation nonetheless constitutes abuse, particularly when it might affect somebody’s wellbeing or deceive non-technical customers,” safety researcher famous.

This discovery highlights the rising significance of securing AI chat interfaces in opposition to conventional net vulnerabilities as they turn out to be extra built-in into on a regular basis workflows and communication channels.

Vulnerability Assault Simulation on How Hackers Quickly Probe Web sites for Entry Factors – Free Webinar

Cyber Security News Tags:Attackers, ChatGPT, Chats, Embed, Images, Lets, Malicious, Shared, SVGs, Vulnerability

Post navigation

Previous Post: Cybercrime-as-a-Service – Countering Accessible Hacking Tools
Next Post: Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts

Related Posts

Microsoft Scripting Engine 0-Day Vulnerability Enables Remote Code Execution Over Network Cyber Security News
Researchers Detailed New Threat-Hunting Techniques to Detect Azure Managed Identity Abuse Cyber Security News
How to Stay Ahead of Vulnerabilities Cyber Security News
Windows DWM 0-Day Vulnerability Allows Attackers to Escalate Privileges Cyber Security News
FortiVoice 0-day Vulnerability Exploited in the Wild to Execute Arbitrary Code Cyber Security News
IXON VPN Client Vulnerability Let Attackers Escalate Privileges Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Telecommunications Companies in Spain Experiencing Downtime
  • Key Insights from the 2025 State of Pentesting Report
  • CloudSEK Raises $19 Million for Threat Intelligence Platform
  • O2 Service Vulnerability Exposed User Location
  • Madhu Gottumukkala Officially Appointed CISA Deputy Director

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2025

Recent Posts

  • Telecommunications Companies in Spain Experiencing Downtime
  • Key Insights from the 2025 State of Pentesting Report
  • CloudSEK Raises $19 Million for Threat Intelligence Platform
  • O2 Service Vulnerability Exposed User Location
  • Madhu Gottumukkala Officially Appointed CISA Deputy Director

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News