Back Gigazine Concerns have been raised that YouTube Studio's AI features could potentially leak ...
Security researcher javoriuski has reported that exploiting YouTube Studio's AI feature 'Ask Studio' could potentially allow someone to send the titles of private videos and other information to an external party through instructions embedded in the section. Leaking YouTube Creators Private Videos | Javox
Ask Studio can provide feedback based on the creator's channel information, meaning that feedback can be obtained not only for public videos but also for draft videos, private videos, and limited-access videos. While convenient, there are some points to be aware of regarding the system that uses AI to read the text in the section. According to javoriuski, if a malicious user wrote instructions for the AI in the section, Ask Studio would sometimes treat the as commands rather than mere opinions. This technique is called 'prompt injection' and is a common problem for services that use AI to read external text. In an experiment conducted by javoriuski, an attacker embedded specific instructions in a , and when a creator clicked on a suggested question in Ask Studio on YouTube Studio, the AI's response displayed the message intended by the attacker. Furthermore, it was shown that by displaying a link to the attacker's website within the AI's response and including the title of a video from the channel in the destination URL, it might be possible to send the titles of private videos to an external server.
The titles of private videos may include unannounced project names, pre-release product reviews, and personal records. Even if the video itself is private, if Ask Studio reads the video titles within the channel and embeds them in an external link based on instructions via the section, there is a possibility that information could be leaked in a way that the creator did not intend. Javoriuski points out that when using AI to read user-submitted content such as , it is necessary to clearly distinguish between the text that the AI processes and the instructions that the AI should follow. Although javoriuski reported the issue to Google, Google treated it as a problem requiring social engineering and did not classify it as a tracked security bug.
Jul 06, 2026 22:00:00 in AI , Web Service , Security , Posted by log1d_ts
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
