HomeTechnologyMicrosoft warns of ‘Whisper Leak’, a flaw that lets attackers infer what users discuss with AI chatbots

Microsoft warns of ‘Whisper Leak’, a flaw that lets attackers infer what users discuss with AI chatbots

The company’s warning serves as a reminder that while encryption protects message content, metadata such as traffic timing and frequency can still expose valuable insights to skilled attackers.

November 13, 2025 / 22:51 IST
Story continues below Advertisement
Microsoft
Microsoft

Microsoft has uncovered a new security vulnerability affecting popular AI chatbots such as ChatGPT and Google’s Gemini, warning that attackers could determine what users are talking about even when conversations are encrypted. The flaw, called “Whisper Leak”, exposes a previously unseen risk in how large language models handle streamed responses.

In its detailed research blog, Microsoft explained that the vulnerability allows third parties such as internet service providers, government agencies, or anyone sharing the same Wi-Fi network to infer the topic of a user’s conversation with an AI system. While attackers cannot read the actual text, they can identify the general subject matter with alarming precision by analysing the patterns and timing of encrypted network traffic.

Story continues below Advertisement

The company warned that the risk is particularly serious in countries where surveillance and censorship are common. By monitoring users’ interactions with chatbots, authorities could detect conversations about politically sensitive or banned topics, including protests, election discussions, or journalism-related content. Microsoft also noted that similar attacks could be used to flag discussions about financial crimes or other high-risk subjects.

The flaw stems from the way chatbots like ChatGPT and Gemini generate responses. Large language models work by predicting and outputting one token at a time, rather than producing an entire response in a single batch. Even though these exchanges are encrypted, the distinctive data flow patterns created during streaming responses can reveal clues about the underlying content.