Privacy Leakage Chains: Prompt Injection in Black-Box Chatbots Enables Multi-Step Data Exfiltration
arXiv·medium signal
LLM-based chatbot agents that combine reasoning with external tools like web browsing create attack surfaces when untrusted external content is processed. This study empirically maps privacy leakage chains where prompt injection in browsed content enables multi-step data exfiltration — from conversation history to uploaded files to connected accounts. Demonstrates complete attack chains in black-box chatbot environments where the attacker never directly interacts with the victim.