Microsoft Discovers Vulnerability That Lets Hackers See ChatGPT and Gemini’s Conversation Topics

Microsoft researchers call the vulnerability in AI chatbots Whisper Leak.

Advertisement
Written by Akash Dutta, Edited by Ketan Pratap | Updated: 11 November 2025 16:27 IST
Highlights
  • It is a new type of side channel attack that works on remote AI models
  • The security flaw lets attackers observe encrypted network traffic
  • Microsoft has also published a paper detailing its findings

Whisper Leak essentially makes use of visible metadata in Transport Layer Security (TLS) encryption

Photo Credit: Unsplash/FlyD

Microsoft has revealed details of a new vulnerability it discovered in most server-based artificial intelligence (AI) chatbots. The vulnerability, dubbed Whisper Leak, is claimed to let attackers learn about the conversation topics an individual has had with AI platforms such as ChatGPT and Gemini. As per the Redmond-based tech giant, the vulnerability can be exploited via a side-channel attack. This attack is said to affect all remote large language model (LLM)-based chatbots. Microsoft said it has worked with multiple vendors to mitigate the risk.

Microsoft Finds a Major Vulnerability in AI Chatbots

In a blog post, the tech giant detailed the Whisper Leak vulnerability and how attackers might exploit it. A detailed analysis of the same has also been published as a study on arXiv. Microsoft researchers claim that the side-channel attack can allow bad actors to observe the user's network traffic to conclude the conversation topics a user has had with these apps and websites. The exploit is said to work even if this data is protected via end-to-end encryption.

Advertisement

The exploit targets both standalone AI chatbots as well as those that are embedded into search engines or other apps. Usually, the Transport Layer Security (TLS) encryption protects the user data when shared with these AI platforms. TLS is a popular encryption technique that is also used in online banking.

During its testing, the researchers found that the metadata of the network traffic, or how the messages move across the Internet, remains visible. The exploit does not try to break open the encryption, but instead, it leverages the metadata that is not hidden.

Advertisement

Microsoft revealed that it tested 28 different LLMs for this vulnerability and was able to find it in 98 percent of them. Essentially, what the researchers did was to analyse the packet size of data and its timing when a user interacts with a chatbot. Then they trained an AI tool to distinguish the target topic based on the data rhythm. The researchers found that the AI system was successfully able to decipher the topics without trying to pry open the encryption.

“Importantly, this is not a cryptographic vulnerability in TLS itself, but rather exploitation of metadata that TLS inherently reveals about encrypted traffic structure and timing,” the study highlighted.

Advertisement

Highlighting the scope of this method, the company claimed that a government agency or Internet service provider (ISP) monitoring traffic to popular AI chatbots could reliably identify users asking questions about topics such as money laundering, political dissent, or other subjects.

Microsoft said it shared its disclosures with affected companies once it was able to confirm its findings. Among the various chatbots that were found to have this vulnerability, the company said OpenAI, Mistral, and xAI have already deployed protections

Advertisement

We have engaged in responsible disclosures with affected vendors and are pleased to report successful collaboration in implementing mitigations. Notably, OpenAI, Mistral, Microsoft, and xAI have deployed protections at the time of writing. This industry-wide response demonstrates the commitment to user privacy across the AI ecosystem.

“OpenAI, and later mirrored by Microsoft Azure, implemented an additional field in the streaming responses under key “obfuscation,” where a random sequence of text of variable length is added to each response. This notably masks the length of each token, and we observed it mitigates the cyberattack effectiveness substantially,” the company said.

For end users, the tech giant recommends avoiding discussing highly sensitive topics with AI chatbots over untrusted networks, using VPN services to add another layer of protection, using non-streaming models of LLMs (on-device LLMs), and opting for chatbot services that have implemented mitigations.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy Book 6 Series Launched in India at These Prices
  2. iQOO Z11 Launched With MediaTek Dimensity 8500 SoC, 9,020mAh Battery
  3. Redmi 15A With 32-Megapixel Rear Camera Debuts in India at This Price
  4. Vivo T5 Pro Price in India Leaked: Here's When It Might Launch
  5. Gemini Update Adds Memory Import, New Chat History Transfer Features
  6. Samsung Expands One UI 8.5 Beta to These Older Galaxy Phones
  7. Meta Might Be Preparing to Launch These New Ray-Ban Smart Glasses Soon
  8. Apple's Foldable iPhone Said to Ship After iPhone 18 Pro Models Debut
  9. Samsung Galaxy A57 5G, A37 5G Price in India, Offers Announced
  1. Brazil Passes Law Allowing Seized Crypto to Fund Public Security Efforts
  2. Google Upgrades Gemini Live With Faster and Smarter Responses, Expands Search Live Globally
  3. Vivo T5 Pro Price in India, Launch Timeline Leaked Online Ahead of Expected Debut
  4. Instagram’s Edits App Updated With Font Inspired By Dhurandhar: The Revenge; Developer Spots Offline Viewing Feature
  5. Oppo K15 Pro, Oppo K15 Pro+ Colourways, Battery and Storage Details Revealed as Smartphones Visit Geekbench
  6. Motorola Razr 70 Ultra Design and Dimensions Revealed via Leaked CAD Renders
  7. Android 17 Beta 3 Hints at New Priority Charging Feature, OEM-Exclusive Camera Features in Third-Party Apps: Report
  8. Bitcoin Trades Near $69,000 as Weak Sentiment Keeps Crypto Market in Check
  9. Samsung Opens One UI 8.5 Beta to More Galaxy Devices, Including Galaxy S24 and Galaxy Z Fold 6
  10. Samsung Galaxy Book 6 Ultra, Galaxy Book 6 Pro Launched in India, Galaxy Book 6 Tags Along: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.