Cybersecurity researchers from Rein Security demonstrated an indirect prompt injection attack that allowed them to bypass safeguards and execute unauthorized code within a major retailer's AI shopping assistant.
Key Points
- Researchers Netanel Rubin and Dan Avraham exploited an AI shopping assistant at one of the three largest U.S. retailers during the Black Hat conference.
- The attack utilized indirect prompt injection, where malicious instructions hidden in external web content tricked the AI into executing unauthorized code.
- Security gaps were identified in the app's search field, which lacked the same protective layers applied to the main chat interface.
- The researchers discovered exposed Google Maps API keys, which could potentially be exploited to incur unauthorized costs on the retailer's account.
- Vulnerabilities were reported to the retailer on March 13, but Rein Security stated the issues remained unpatched as of July 16.