AI Recommendation Poisoning via 'Ask AI' Buttons Exploiting LLM Memory Manipulation
A new AI security vulnerability allows attackers to manipulate large language models (LLMs) by embedding malicious prompts in 'Ask AI' buttons, altering their memory to favor specific vendors. The technique, classified as AI Recommendation Poisoning, exploits deep-linking and persistent memory features in AI assistants without user consent.
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links.
We observed production websites embedding hidden prompt injection payloads inside "Ask AI" buttons on marketing and competitor comparison pages. When a user
*** END OF TRANSMISSION ***