A recently discovered attack vector exploits a standard feature in major AI assistants, leveraging pre-filled deep links to inject malicious prompts. This technique, known as AI recommendation poisoning, allows attackers to silently alter the memory of large language models (LLMs) without requiring malware, stolen credentials, or zero-day exploits. By embedding hidden prompt injection payloads within "Ask AI" buttons on websites, attackers can manipulate user interactions and influence the recommendations provided by AI assistants. This vulnerability is particularly concerning as it can be used to spread disinformation or manipulate user behavior, all without being detected by traditional security measures1. The fact that this attack vector is being used in production websites, including marketing and competitor comparison pages, highlights the need for defenders to be aware of this emerging threat. This matters to practitioners as it underscores the importance of monitoring AI-powered systems for potential manipulation and taking proactive measures to prevent such attacks.
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
⚠️ Critical Alert
Why This Matters
Zero-day exploitation means the vulnerability is being used before patches exist — defenders are already behind.
References
- The Hacker News. (2026, August 6). AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory. *The Hacker News*. https://thehackernews.com/2026/08/ai-recommendation-poisoning-how-ask-ai.html
Original Source
The Hacker News
Read original →