Grok Has "Encrypted Context Injection" Vulnerability, User Chat Data at Risk of Leakage
According to Cryptopolitan, cybersecurity firm Adversa AI has disclosed a security vulnerability in xAI's AI assistant Grok, dubbed "encrypted context injection." Attackers can hide encrypted instructions within ordinary…
According to Cryptopolitan, cybersecurity firm Adversa AI has disclosed a security vulnerability in xAI's AI assistant Grok, dubbed "encrypted context injection." Attackers can hide encrypted instructions within ordinary web pages; when a user asks Grok to summarize the page, Grok automatically decrypts and executes the hidden commands, sending the user's name, geographic location, subscription tier, and full chat history to the attacker's server. The vulnerability was disclosed to xAI via the HackerOne platform on June 3, 2026, with researcher Rony Utevsky following up on August 4 and 10, but as of August 19, the flaw remains unpatched on Grok.com, and xAI has not provided a timeline for a fix.
insigtX content is informational and educational, not investment advice.