OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
By [email protected] (The Hacker News)
AI Summary
Researchers disclosed a flaw affecting reasoning APIs from OpenAI, Anthropic, and Google whereby encrypted reasoning objects ('thinking blocks') generated in one session could be replayed into another session, allowing weaker AI models to decode the internal reasoning of stronger models and recover secrets such as API keys and passwords embedded in session logs. The vulnerability stems from how providers transport hidden reasoning between API calls without sufficient session binding. Developers using reasoning-enabled APIs should audit session logs and rotate any secrets that may have been exposed.
Relevance score: 84.0/100
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →