Researcher Demonstrates Prompt Injection Vulnerability in YouTube Studio AI (javoriuski.com)
0xBASE INTEL BRIEF
- YouTube Studio AI can be manipulated via comments due to lack of separation between user content and system prompts.
- An attacker can leave a comment that tricks the AI into outputting attacker-controlled text, and even construct links that exfiltrate private video titles.
- Google classified the report as social engineering and declined to fix; the researcher believes it is a trust model violation.
"A security researcher discovered a prompt injection vulnerability in YouTube Studio's Ask Studio AI assistant. By leaving specially crafted comments on videos, an attacker can make the AI output attacker-controlled text, including links that leak private video titles. Google dismissed the report as social engineering, but the researcher argues it exploits trust in Google's product. The vulnerability remains unpatched."
no comments yet.