HomeSecurityLenovo: AI customer service chatbot breached

Lenovo: AI customer service chatbot breach

Critical vulnerabilities have been identified in Lenovo's AI-powered customer service chatbot, "Lena," allowing attackers to steal session cookies and (potentially) gain unauthorized access to customer support the company's

Lenovo: AI chatbot breach

Cybernews researchers discovered that Lenovo’s chatbot, powered by OpenAI’s GPT-4, was vulnerable to cross-site scripting (XSS) attacks due to improper input and output sanitization. The vulnerability allowed attackers to inject malicious code via a carefully crafted 400-character command that tricked the AI ​​system into generating malicious HTML content.

“Everyone knows that chatbots can be fooled by prompt injections. This is nothing new,” the Cybernews in a report. “What is truly concerning is that Lenovo, despite being aware of these vulnerabilities, did not protect itself from potentially malicious user manipulations and chatbot outputs.” Lenovo has not commented on the findings.

See also: Chrome vulnerability allows malicious code execution

Lenovo AI chatbot breach: How the attack worked

The researchers' attack involved tricking the chatbot into generating malicious HTML code via a command that began with a legitimate product inquiry. It included instructions to convert responses to HTML format and embedded code designed to steal session cookies when images failed to load.

When Lenovo's Lena received the malicious command, the researchers noted that "the desire to please the user (people-pleasing) is the issue that haunts large language models, to such an extent that, in this case, Lena accepted our malicious payload, which produced the XSS vulnerability and allowed the capture of session cookies."

Lenovo: AI customer service chatbot breach

Melissa Ruzzi, AI director at security firm AppOmni, said the incident highlighted “the well-known issue of prompt injection in Generative AI.” She warned that “it’s critical to oversee all data that AI has access to, which typically includes not only read permissions, but also the ability to edit. This could make this type of attack even more devastating.”

Lenovo chatbot breach: Business-wide impacts

While the immediate impact included the theft of session cookies, the implications of the vulnerability extended far beyond data extraction. The researchers warned that the same vulnerability could allow attackers to modify support interfaces, deploy keyloggers, attacks phishing , and execute system commands that could install backdoors and allow lateral movement throughout the network infrastructure.

See also: CodeRabbit: Vulnerability allowed access to 1 million repositories

“Using the stolen agent's session cookie, it is possible to log in to the customer support system with the agent's account,” the researchers explained.

Balance between innovation and security

The Lenovo vulnerability exemplified the security challenges that arise when organizations rapidly deploy AI technologies without adequate security frameworks. Arjun Chauhan, an executive at Everest Group, warned that “the risk profile is fundamentally different” with AI systems because “models behave unpredictably under adversarial inputs.”

Recent industry data showed that automated bot traffic surpassed human-generated traffic for the first time, accounting for 51% of total internet traffic in 2024.

See also: Clickjacking: Vulnerabilities in popular passwordmanagers

Lenovo: AI customer service chatbot breach

Ruzzi noted that “AI chatbots can be thought of as another SaaS application, where data access misconfigurations can easily turn into data breaches.” She emphasized that “more than ever, security needs to be an inherent part of all AI implementations. While there is pressure to release AI features as quickly as possible, this should not come at the expense of data security.”

Lenovo has fixed the vulnerability after researchers responsibly disclosed it.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS