🟠 High | Source: The Hacker News
A newly documented prompt injection technique embeds hidden instructions inside ‘Ask AI’ deep-link buttons on commercial websites, causing AI assistants to silently absorb attacker-controlled content into their memory or context. The attack requires no malware, exploits, or compromised credentials — only a user clicking a standard-looking button. This is particularly concerning because it can manipulate AI-driven recommendations and persist across user sessions if memory features are enabled.
Security Architect’s Take: Audit any enterprise AI assistant deployments (e.g. ChatGPT, Copilot, Gemini) to understand whether persistent memory or deep-link pre-filling is enabled for users; consider disabling or restricting memory features and enforcing content security policies that block untrusted deep-link invocations in your organisation’s browser fleet.
Original advisory: AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory