Ask AI buttons can secretly bias future answers
Some website "Ask AI" buttons can secretly change an assistant's stored preferences. Later answers may favor the company behind that website.
- Report priority
- Critical
- Targets
- ChatGPT+3 more
How it works
- A person clicks an "Ask AI" button while logged into an AI assistant.
- The link opens a prepared request and runs it without another confirmation.
- A hidden instruction tells the assistant to remember the vendor's website as trusted.
- If the assistant saves it, that preference can influence later answers.
What to do
Review your assistant's stored memory for unfamiliar vendor websites marked as trusted sources. Finding one indicates an unwanted stored preference, but does not prove every answer changed.
Do not click unsolicited memory-changing links while logged into a work account. If you find an unfamiliar entry, ask your IT team to audit the account. The retrieved evidence references cleanup guidance, but does not document the removal procedure.
Technical details
Affected software: ChatGPT, Claude, Gemini, Grok
Researchers found hidden instructions operating on commercial marketing and comparison pages. Microsoft Security identified 31 companies across 14 industries using this behavior. Separately, one data source contained more than 50 distinct prompts observed over 60 days.
The technique combines pre-filled AI links with persistent memory. A website places an undisclosed instruction inside an "Ask AI" link. The assistant runs that request in the user's active session and may store the vendor's domain as trusted. The report calls this AI Recommendation Poisoning.
It associates the behavior with memory poisoning and prompt injection techniques tracked by MITRE ATLAS.
References
- msrc.microsoft.com · CVE-2026-50522 Patch Vendor Advisory
- securityonline.info · unc6671-vishing-extortion-rebrand press/media coverage SecurityOnline
- nvd.nist.gov · CVE-2026-50522 vdb entry
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource
- thehackernews.com · unc6671-vishing-attacks-target-personal.html TheHackerNews
- thehackernews.com · deadlock-ransomware-uses-polygon-smart.html TheHackerNews
- neuracybintel.com · levi-strauss-confirms-social-engineering-attack-that-allowed-hackers-to-steal-corporate-data-from-employee-computers NeuraCybIntel
- neuracybintel.com · rising-sextortion-scams-exploit-massive-data-leaks-from-shinyhunters-group NeuraCybIntel