LIVE · cybersecurity feed
Live wire

chatbot vulnerability

ai securityhigh

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI has detailed a new attack called Cryptographic Context Injection that can trick xAI's Grok chatbot into sending user data, including name, location, subscription tier, and conversation history, to an attacker-controlled server. The attack exploits the chatbot's Python execution runtime by embedding encrypted instructions that Grok decrypts and executes, leading it to construct a URL containing the sensitive information. While Adversa AI has reported the vulnerability to xAI, there is currently no patch or CVE identifier, and no public statement from xAI regarding mitigation.