AI Shopping Assistant Vulnerabilities Enable Remote Code Execution on Retailer’s Servers
ID: e3029535-d96c-5a03-96af-8a852e6cec5e
STIX ID: report--e3029535-d96c-5a03-96af-8a852e6cec5e
Feed Name: GBHackers
Security researchers demonstrated how flaws in a major U.S. retailer's AI shopping assistant (mobile app) allowed them to bypass intent-filtering, obtain hidden inputs, and achieve remote code execution on backend infrastructure; they confirmed live Python execution and access to environment variables and discovered unrestricted Google Maps API keys. The issues were disclosed but reportedly classified by the retailer as intended behavior and remained unresolved after the 90-day disclosure window.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
