As cited
Copy frozen at (site build).
ai security
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI disclosed a cryptographic context injection attack that could trick xAI's Grok chatbot into exfiltrating sensitive user data, including names, locations, subscription tiers, and conversation prompts, when users ask it to summarize web pages. The technique exploits Grok's ability to process web content and relay information to attacker-controlled servers.
Why it matters: Users of Grok and developers integrating large language models (LLMs) into web-facing applications need to understand how malicious web content can weaponize context processing to extract personal and conversational data.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa artificial intelligence (AI) disclosed a cryptographic context injection attack that could trick xAI's Grok chatbot into sending user data, including name, location, subscription tier, and conversation prompts, to an attacker-controlled server when processing requests to summarize web pages. The technique exploits how Grok processes external content to exfiltrate sensitive information from ongoing chat sessions.
Why it matters: Organizations and individuals using Grok for sensitive conversations face exposure of personal data and chat history through malicious web pages; security teams should evaluate risks when users access chatbot services that process untrusted external content.
- Source published
- First seen by Cybersecurity Tracker