The Chameleon's Trap: AI-Triggered Zero-Click Vulnerability
Is this a scandal?
No longer — the story has resolved. Noise 1/100, cooling down, across 0 sources.
Microsoft and OpenAI are likely to implement more rigorous sandboxing for link-crawling within the next few weeks. We should expect a wave of browser updates that default 'automatic downloads' to 'off' for all users regardless of site reputation.
Noise 1/100 — louder than 86% of tracked AI controversies.
Why it matters
This exploit demonstrates how LLMs can be weaponized as 'trusted intermediaries' to bypass traditional browser security and human skepticism. It highlights a critical failure in how AI models verify external links before recommending them to users.
Key points
- The 'Chameleon's Trap' campaign tricks AI scanners into white-listing malicious links embedded on websites.
- The exploit leverages browser 'automatic download' settings to deliver payloads without explicit user confirmation.
- On Windows 11, the attack utilizes a variant of the Follina vulnerability to execute code via PowerShell when a file is hovered over.
- The vulnerability effectively uses ChatGPT and other LLMs as a 'shield' to build false trust with the victim.
- Security experts recommend disabling 'automatic downloads' and 'trusted site' shortcuts in all major browsers.
The story
A new phishing campaign dubbed 'Chameleon's Trap' has been identified, utilizing a sophisticated method to bypass security scans performed by AI models like ChatGPT. The attack involves embedding hidden links on websites that AI crawlers incorrectly categorize as safe, leading the AI to recommend these links to users. Once a user clicks the AI-recommended link, a file is automatically downloaded via browser 'trusted site' defaults. On Windows 11 systems, the exploit reportedly leverages vulnerabilities similar to the Follina (CVE-2022-30190) flaw, where merely hovering over a file in the file explorer can trigger malicious PowerShell commands. These commands grant attackers user-level privileges, effectively bypassing Microsoft's standard security protocols. Security researchers are now urging users to disable automatic downloads in browser settings to mitigate the risk of these zero-click execution chains initiated through AI interactions.
Who's involved
Warning that current AI link-scanning is insufficient and that browser 'auto-download' features create a massive security hole.
Providing a service that is being exploited by third parties to recommend malicious links as safe content.
Managing the Windows 11 and MSDT vulnerabilities that allow the PowerShell execution once the file is downloaded.
Noise Level
The timeline
- 6 months ago
Initial Chameleon's Trap Reports
Earliest instances of the phishing campaign using AI crawlers as a bypass method begin to surface.
Public Warning Issued
A high-level warning is circulated on social platforms regarding zero-click exploits triggered by AI recommendations.
CVE-2022-30190 (Follina) Discovered
A remote code execution vulnerability in the Microsoft Support Diagnostic Tool is first identified.
The full record
What's being under-reported
No defender-side coverage yet
The critic side is sourced here; no defending voice has been captured yet.
- Coverage: 0 social posts, 0 news-outlet items.
- Voices: 1 critic, 0 defenders.
The forecast
Microsoft and OpenAI are likely to implement more rigorous sandboxing for link-crawling within the next few weeks. We should expect a wave of browser updates that default 'automatic downloads' to 'off' for all users regardless of site reputation.
Forecast, not fact — an editorial estimate we score when this resolves.
That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.
Join the Discussion
Discuss this story
Community comments coming in a future update
Be the first to share your perspective. Subscribe to comment.