Microsoft researchers have uncovered a significant security flaw affecting popular AI chatbots that could allow hackers to intercept encrypted conversations. Despite the use of strong encryption, the vulnerability, termed “Whisper Leak,” enables attackers monitoring network traffic to infer the topics users discuss with AI chatbots. This side-channel attack analyzes patterns such as packet sizes and timing intervals of encrypted data as it streams between users and AI services, revealing sensitive conversation themes without decrypting the actual messages.
The research highlights that entities capable of observing internet traffic—such as government agencies, ISPs, or attackers on local networks—could exploit this flaw to detect conversations about confidential matters, including financial crimes, political dissent, or other monitored topics. While the exact content of chats remains secure, the metadata leak compromises privacy and raises concerns about the security of AI chatbot communications.
This discovery emphasizes that encryption alone cannot guarantee privacy when traffic patterns can be analyzed to expose information indirectly. Microsoft’s findings advocate for heightened scrutiny over AI systems’ operational security, particularly as they become increasingly integrated into sensitive and personal digital interactions. Users engaging in highly confidential conversations with AI models may need to reassess the risks or seek more robust protections until these vulnerabilities are addressed.