US Retail Giant's AI Assistant Bypassed: Code Execution

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Two researchers have achieved code execution within the environment of a shopping assistant accessible from the public app of one of the three largest American retailers, according to Rein Security. As of July 16, more than 90 days after the initial report, Rein claims that the vulnerabilities had not been patched. The attack exploited an indirect prompt injection and a less protected input, set against a backdrop of surveillance blind spots and visible Google Maps keys in mobile traffic. The retailer is not named.
Missing Fixes as of July 16 and Incomplete Visibility on AI
As of July 16, more than 90 days after the first report, Rein Security indicated that the vulnerabilities had not been addressed and did not provide a more recent public update. In this case, the retailer's security system was monitoring interactions with the assistant, but according to Rein, it did not see the retrieved information or the tools used, creating a blind spot between the conversation and the background actions.
During their analysis, the researchers also found Google Maps API keys visible in the decrypted traffic of the mobile app. If these keys were not properly restricted, they could be used for unauthorized requests to Google Maps services on the retailer's account, potentially incurring charges or exhausting quotas. The researchers did not report accessing customer data through these keys.
AI Filter Bypassed via Less Protected Input
The retailer had implemented a security layer and an AI agent filtering requests to keep the assistant within its role, with possible rejection of out-of-scope requests. However, the protections were not uniform: the chat interface displayed safeguards that the search field did not apply at the same level. Through this less protected input, the researchers claim to have obtained details about the internal configuration of the assistant, including the names of available tools and the syntax for calling them.
The initial entry point was product comparison, a function for which the AI retrieves content from external sites beyond the retailer's control. The researchers inserted instructions into content they controlled and prompted the assistant to load it. The AI then processed part of this material as directives, a technique known as indirect prompt injection. This step alone was not sufficient to reach the system behind the assistant, but it provided the starting point for the attack.
Code Execution and System Information Leaks
After bypassing the protections, the researchers led the assistant to execute code within its own environment. The bot returned lists of directories, environment variables, and other internal information, demonstrating, according to them, that the injection had worked. They deliberately triggered a division by zero, and the resulting Python error helped confirm the effective execution of the code.
The transition to code execution crosses a significant security boundary, regardless of the exact nature of the technical information returned.
Unspecified Scope and Researchers' Intervention Framework
Rein's public account does not specify the potential accesses of the assistant's isolated environment nor the possibility of transitioning to systems containing customer, payment, or inventory data. The researchers claim they neither accessed actual customer information, nor modified orders, nor attempted to disrupt systems, as their tests were conducted in a controlled environment with their own session.
Rein did not identify the retailer, citing legal reasons, which prevents independent verification with the company and does not allow customers to know if they have used the affected assistant. The researchers are not revealing which application is impacted at this time.
More Powerful Assistants, Increased Risks, and User Advice
In addition to generating responses, these assistants are capable of collecting data, interacting with third-party services, and using various software tools. Some retailers anticipate that they could compile shopping lists, check stock status, manage orders, and facilitate purchase validation. However, the addition of each new feature increases the risk that the AI could be abused to execute inappropriate instructions. A typical user has few means to protect against such vulnerabilities, as the attack targets how the system is designed. The responsibility lies with the companies that open access to internal tools and information: they must assume that content retrieved from the open Internet may contain hostile directives and implement appropriate protections. As a precaution, it is advisable to limit personal information shared with these assistants and to keep retail applications updated to receive patches. The technical information obtained could, in cases of abuse, provide clues about systems and expose secrets or access, potentially impacting the company and its customers. The demonstration illustrates what can happen as these tools gain more control.
Who, Where, and What: Black Hat, Rein Security, and an Anonymous Giant
The presentation took place at Black Hat USA 2026 in Las Vegas, led by Netanel Rubin and Dan Avraham. Their work focuses on an AI shopping assistant used by a major American retailer that, according to Rein Security, is among the three largest in the United States and whose bot was accessible via the public mobile app. Rein Security also markets technologies for monitoring AI agents.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.