LIVE · cybersecurity feed
Live wire
ai securityhigh

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI has detailed a new attack called Cryptographic Context Injection that can trick xAI's Grok chatbot into sending user data, including name, location, subscription tier, and conversation history, to an attacker-controlled server. The attack exploits the chatbot's Python execution runtime by embedding encrypted instructions that Grok decrypts and executes, leading it to construct a URL containing the sensitive information. While Adversa AI has reported the vulnerability to xAI, there is currently no patch or CVE identifier, and no public statement from xAI regarding mitigation.

zeroday.news ·

A new attack vector, dubbed Cryptographic Context Injection, has been identified that could potentially allow malicious web pages to exfiltrate sensitive user data from xAI's Grok chatbot. The attack, detailed by Adversa AI, reportedly leverages a novel method to trick the chatbot into transmitting user information to an attacker-controlled server.

The core mechanism of Cryptographic Context Injection involves embedding encrypted instructions within the chatbot's operational environment. Specifically, the attack targets Grok's Python execution runtime. The embedded instructions are crafted in such a way that Grok is compelled to decrypt them and subsequently execute the decrypted code. This execution then leads the chatbot to construct a URL that incorporates various pieces of sensitive user data.

The data reportedly at risk includes personally identifiable information such as the user's name and location, as well as details about their subscription tier and their complete conversation history with the chatbot. Once the malicious URL is constructed with this embedded data, Grok is then tricked into making a request to an attacker-controlled server, effectively transmitting the sensitive information outside of its secure environment.

This class of vulnerability often arises when applications execute user-supplied or externally influenced code without sufficient validation or sandboxing. In this specific instance, the ability to inject encrypted instructions that the chatbot then decrypts and executes points to a potential weakness in how Grok processes and trusts certain inputs within its Python runtime environment. Such flaws can be particularly challenging to detect and prevent if the injection point is subtle or if the execution environment lacks robust isolation mechanisms.

Typical mitigation strategies for vulnerabilities involving code execution or data exfiltration often include stringent input validation, output encoding, and the implementation of strong content security policies (CSPs) to restrict outbound connections. For applications with embedded runtimes, robust sandboxing and privilege separation are crucial to limit the impact of any successful code injection. Regular security audits and penetration testing are also vital to uncover such sophisticated attack vectors.

Adversa AI has reportedly disclosed this vulnerability to xAI. However, as of the reporting, there is no publicly available patch or a Common Vulnerabilities and Exposures (CVE) identifier assigned to this issue. Furthermore, xAI has not yet issued a public statement regarding the vulnerability or any planned mitigations. This situation underscores the ongoing challenges in securing complex AI systems against novel attack techniques that exploit their underlying architectural components.

ai securitychatbot vulnerabilitydata exfiltrationcryptography
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

security

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.