Researchers show one link can hijack a ChatGPT agent's identity
Security firm Zenity Labs disclosed 'AgentForger,' a vulnerability in OpenAI's Agent Builder where a single manipulated ChatGPT link could spawn an autonomous agent acting under a victim's identity. The rogue agent inherited the victim's access rights, bypassed approval requirements via a malicious prompt, and pulled new instructions from the attacker's inbox every five minutes.
Why it matters: This is a concrete case of prompt injection escalating into full account takeover once an agent has standing permissions and a persistent instruction channel — exactly the failure mode safety researchers have been flagging as agentic tools get real write access. It's a preview of the security scrutiny every agent-builder platform, not just OpenAI's, will need to withstand.