Interestana
Home/News/New AI Prompt Injection Abuses "Ask AI" Buttons
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

New AI Prompt Injection Abuses "Ask AI" Buttons

New AI Prompt Injection Abuses "Ask AI" Buttons

A new category of prompt injection, termed "recommendation poisoning," has emerged, targeting the memory of Large Language Models (LLMs) through standard website features. This attack vector bypasses traditional security measures, requiring neither malware, compromised credentials, nor zero-day vulnerabilities. Instead, it leverages pre-filled deep links, a common component integrated into nearly every major AI assistant. Researchers observed production websites embedding hidden prompt injection payloads within "Ask AI" buttons, particularly on marketing and competitor comparison pages. When a user interacts with these buttons, the embedded prompts are silently executed, influencing the LLM's subsequent responses and potentially altering its perceived knowledge base or biases. This method effectively "poisons" the AI's recommendation engine by subtly manipulating the context it receives. The attack is particularly insidious because it operates without user awareness, appearing as a legitimate feature designed to enhance user interaction with AI assistants. The implications of this vulnerability are significant, as it can lead to the dissemination of biased information, skewed product recommendations, or even the generation of misinformation, all originating from seemingly innocuous website elements. The technique exploits the trust users place in AI assistants and the standard functionality of web design, making it difficult to detect and mitigate. Unlike traditional prompt injection attacks that might require direct user input or complex social engineering, recommendation poisoning operates in the background, silently corrupting the AI's operational memory. This could have far-reaching consequences for businesses relying on AI for customer service, content generation, or market analysis, as the AI's output could be subtly steered by malicious actors. The research highlights a critical gap in current AI security protocols, which often focus on protecting the AI model itself rather than the integrity of the data and interaction pathways it uses. The widespread adoption of "Ask AI" buttons and similar deep-linking features across e-commerce, informational, and service-oriented websites means that a vast number of LLMs are potentially exposed to this threat. The attack vector's simplicity and reliance on existing web infrastructure make it a scalable and persistent risk. Further investigation is needed to develop robust defenses against this novel form of AI manipulation, ensuring the reliability and trustworthiness of AI-generated information and recommendations.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next