CYBERSECURITYTRACKER
TRACKING7,218 stories in this site build1,512 vulnerability news stories in this site build
Permanent story citation

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3979

As cited

Copy frozen at (site build).

ai security

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

Security researchers identified a prompt injection attack vector leveraging pre-filled deep links embedded in "Ask AI" buttons on commercial websites. The attack requires no malware or credentials and exploits a standard feature in major AI assistants to inject malicious prompts that influence language model responses.

Why it matters: Organizations deploying AI assistant integrations and users relying on AI recommendations need to understand how third-party websites can manipulate AI responses through hidden prompt injection, affecting the reliability of AI-assisted decisions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

Researchers identified a new prompt injection attack class that embeds malicious payloads in 'Ask artificial intelligence (AI)' buttons on commercial websites. The technique exploits pre-filled deep links built into major AI assistants and requires no malware, credentials, or zero-day exploits. The method allows attackers to silently alter how language models (LLMs) respond by poisoning recommendation data on marketing and competitor comparison pages.

Why it matters: Organizations hosting AI recommendation features and users interacting with embedded AI buttons face poisoned responses and manipulated comparisons. Security teams should audit deep link implementations in AI integrations and validate that user-submitted prompts cannot be injected through URL parameters or pre-filled content.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary