Named anchors in URLs can be used for prompt injection in AI browser assistants. # URL parts are only evaluated in browser, and not send to servers. AI assistants in browsers do read them though.
3 Matching Annotations
- Last 7 days
-
www.csoonline.com www.csoonline.com
- Apr 2023
-
greshake.github.io greshake.github.io
-
https://web.archive.org/web/20230404050349/https://greshake.github.io/
This site goes with this paper <br /> https://doi.org/10.48550/arXiv.2302.12173
The screenshot shows a curious error which makes me a little bit suspicious: the reverse Axelendaer is not rednelexa, there's an a missing.
-
If allowed by the user, Bing Chat can see currently open websites.
The mechanism needs a consent step from the user: to allow Bing Chat to see currently open websites. And one of those websites already open, needs to contain the promptinjection.
Tags
Annotators
URL
-