AUTO-UPDATED

Hackers Tricked a Major Retailer’s AI Shopping Bot to Do Something It Was Never Supposed To

Cybersecurity researchers from Rein Security demonstrated an indirect prompt injection attack that allowed them to bypass safeguards and execute unauthorized code within a major retailer's AI shopping assistant.

Key Points

  • Researchers Netanel Rubin and Dan Avraham exploited an AI shopping assistant at one of the three largest U.S. retailers during the Black Hat conference.
  • The attack utilized indirect prompt injection, where malicious instructions hidden in external web content tricked the AI into executing unauthorized code.
  • Security gaps were identified in the app's search field, which lacked the same protective layers applied to the main chat interface.
  • The researchers discovered exposed Google Maps API keys, which could potentially be exploited to incur unauthorized costs on the retailer's account.
  • Vulnerabilities were reported to the retailer on March 13, but Rein Security stated the issues remained unpatched as of July 16.

Why it Matters

This incident highlights a critical security blind spot as companies grant AI agents increasing access to internal tools and sensitive backend systems. It demonstrates that current safeguards often fail to account for malicious instructions embedded in external data, posing significant risks to both corporate infrastructure and customer data privacy.
CNET Published by Nelson Aguilar
Read original