New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
The Hacker News
Read full postAdversa AI revealed a cryptographic context injection attack on xAI's Grok chatbot that can exfiltrate user data including name, location, subscription tier, and chat prompts to an attacker server without user consent. The attack exploits Grok's ability to decrypt encrypted instructions and execute them, bypassing content filters, and has a 40% success rate in tests on Grok 4.5 Fast as of August 19, 2026.




