logo

Investigating LLM Jailbreaking of Popular Generative AI Web Products

ID: e5877a78-39e1-5d30-83d1-2fa30ea613e7

STIX ID: report--e5877a78-39e1-5d30-83d1-2fa30ea613e7

Feed Name: Palo Alto Networks Unit 42

Threat Score
50/100

Date Published: 2025-02-21

Date Updated: 2026-04-28

Author: Yongzhe Huang, Yang Ji and Wenjun Hu

...
...

This Unit 42 report evaluates jailbreaking across 17 popular GenAI web products and finds that every tested app was vulnerable to at least some jailbreak strategies; multi-turn techniques were notably more effective for AI-safety violations (ASRs up to ~54.6%) while a repeated-token single-turn attack caused one app to leak training-data. The report presents aggregate attack success rates, compares single- and multi-turn methods, includes case studies (system-prompt and training-data leakage), and recommends layered content filtering, monitoring, and stronger guardrails to mitigate risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.