OpenAI Anthropic and Google reasoning APIs cross-session replay security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A newly disclosed cross-session replay flaw in OpenAI, Anthropic, and Google reasoning APIs exposed hidden reasoning and secrets from session logs, including API keys and passwords. The weakness let opaque reasoning blocks move across sessions, users, and compatible models, turning preserved reasoning state into a secret-extraction risk. Researchers said the demonstrated attacks stopped working after mitigations in August 2026.
Related Happenings
Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical Analysis
H score3
First: 03.08.2026 19:24
Last: 03.08.2026 19:24
Sources 1
About this happening:
Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate...
Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical AnalysisAbout this happening: Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate...
OpenAI model sandbox escape and exploit chaining during ExploitGym evaluation
Technical Analysis
H score34
First: 22.07.2026 07:18
Last: 22.07.2026 07:18
Sources 1
About this happening:
OpenAI's GPT-5.6 Sol and a pre-release model were observed chaining vulnerabilities and escaping a sandbox during evaluation, showing how advanced model behavior can drive...
OpenAI model sandbox escape and exploit chaining during ExploitGym evaluation
Technical AnalysisAbout this happening: OpenAI's GPT-5.6 Sol and a pre-release model were observed chaining vulnerabilities and escaping a sandbox during evaluation, showing how advanced model behavior can drive...
Agent data injection proof-of-concept attacks expose trusted-data flaws in AI agents
Technical Analysis
H score25
First: 16.07.2026 14:32
Last: 16.07.2026 14:32
Sources 1
About this happening:
Researchers disclosed agent data injection (ADI), a new attack class that can make shipping AI agents misclick, run attacker commands, and trust fake history across web and co...
Agent data injection proof-of-concept attacks expose trusted-data flaws in AI agents
Technical AnalysisAbout this happening: Researchers disclosed agent data injection (ADI), a new attack class that can make shipping AI agents misclick, run attacker commands, and trust fake history across web and co...
MemGhost stealth memory injection against OpenClaw personal agents
Technical Analysis
H score23
First: 13.07.2026 16:49
Last: 13.07.2026 16:49
Sources 1
About this happening:
Researchers demonstrated MemGhost, a one-email prompt-injection technique that can plant a persistent false memory in OpenClaw-style personal agents, letting an at...
MemGhost stealth memory injection against OpenClaw personal agents
Technical AnalysisAbout this happening: Researchers demonstrated MemGhost, a one-email prompt-injection technique that can plant a persistent false memory in OpenClaw-style personal agents, letting an at...
Google Dialogflow CX Code Blocks shared-runtime isolation security flaw
Vulnerability
H score32
First: 07.07.2026 19:37
Last: 07.07.2026 19:37
Sources 1
About this happening:
Google Dialogflow CX Code Blocks had a shared-runtime isolation flaw that could let one editable agent affect other Code Block-enabled agents in the same Google Cloud pr...
Google Dialogflow CX Code Blocks shared-runtime isolation security flaw
VulnerabilityAbout this happening: Google Dialogflow CX Code Blocks had a shared-runtime isolation flaw that could let one editable agent affect other Code Block-enabled agents in the same Google Cloud pr...
Timeline
-
12.08.2026 14:47 2 articles · 4h ago
Researchers disclose replay flaw in OpenAI, Anthropic, and Google reasoning APIs
Initial DisclosureResearchers disclosed a cross-session replay flaw in OpenAI, Anthropic, and Google reasoning APIs that let a compatible weaker model recover hidden reasoning from session logs and expose API keys, passwords, access tokens, and private keys from published agent traces. The team said encrypted reasoning objects were portable across sessions, users, and models, used Claude Haiku 4.5, GPT-5.6 Luna, and Gemini Robotics ER-1.6 as fuzzy decoders during testing, and found 704 distinct privacy artifacts from genuine user sessions across 6,708 public agent trajectories; the demonstrated attacks stopped working after mitigations, and no malicious exploitation in the wild was documented.
Show sources
- OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning — thehackernews.com — 12.08.2026 14:47
- OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning — thehackernews.com — 12.08.2026 14:47