Counterfeiting for support and replacement of comments. Security researcher found a dangerous vulnerability in YouTube robot

Ask Studio is built into YouTube Studio and helps the authors to disassemble the statistics of the channel, as well as briefly retell the comments of the audience. Javox checked what would happen if the comment contains no ordinary review, but an instruction for AI. After several attempts, the researcher found a working wording: the message was disguised as a comment from the YouTube support service and asked the assistant to begin a retelling with an important notification from the platform.

A potential attack is based on editing comments. The attacker can first leave a harmless remark, and later replace the text with a hidden command for AI. YouTube does not warn the channel’s authors of comment editing, so the owner of the channel may not notice the substitution before asking for Ask Studio.

After a request for a retelling of comments, the AI will add in response the text given to the attacker. In the demonstration, Javox went further and asked the assistant to form a link to an external site, replacing part of the address with the name of one of the videos on the channel. Ask Studio made the instructions and substituted the name of the real private video into the link, since the assistant has access to the author's channel data.


The names of private videos may disclose unpublished materials, personal entries or confidential projects. To attack, you do not need to hack YouTube or access the account: it is enough to force a trusted AI assistant to use the comment as a command, and then wait for the action of the channel’s author.

Javox reported on the problem of Google, but the company did not take into account the find as a security error. In terms of Google’s position, the risk requires interaction on the part of the victim and treats social engineering rather. The researcher did not agree with the assessment: according to Javox, the authors of the channels interact not with the attacker directly, but with the official AI-tool tool YouTube, which is trusted by default.

Javox believes that YouTube should consider comments as untrusted data and limit the impact of user text on Ask Studio responses. Without additional protection, the AI assistant can turn into a channel of information leakage, even if the original function is intended only for convenient audience analysis.
 
Top Bottom