CYBERSECURITYTRACKER
TRACKING
Permanent story citation

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4786

As cited

Copy frozen at (site build).

ai security

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI disclosed a cryptographic context injection attack that could trick xAI's Grok chatbot into exfiltrating sensitive user data, including names, locations, subscription tiers, and conversation prompts, when users ask it to summarize web pages. The technique exploits Grok's ability to process web content and relay information to attacker-controlled servers.

Why it matters: Users of Grok and developers integrating large language models (LLMs) into web-facing applications need to understand how malicious web content can weaponize context processing to extract personal and conversational data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa artificial intelligence (AI) disclosed a cryptographic context injection attack that could trick xAI's Grok chatbot into sending user data, including name, location, subscription tier, and conversation prompts, to an attacker-controlled server when processing requests to summarize web pages. The technique exploits how Grok processes external content to exfiltrate sensitive information from ongoing chat sessions.

Why it matters: Organizations and individuals using Grok for sensitive conversations face exposure of personal data and chat history through malicious web pages; security teams should evaluate risks when users access chatbot services that process untrusted external content.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary