Ethical Hacking News
A new cryptographic context injection attack has exposed a significant vulnerability in the Grok chatbot, allowing attackers to steal sensitive information from user sessions. The attack, discovered by Adversa AI, has significant implications for the security of chatbots and AI-powered systems, highlighting the need for better security measures and governance to protect against such attacks.
The Grok chatbot, a popular AI-powered chatbot, has been discovered to be vulnerable to a new attack called "Cryptographic Context Injection" that allows attackers to steal sensitive information. The vulnerability is due to the way the chatbot handles encrypted data from external sources, making it difficult for users to detect the attack. The attack works by injecting encrypted data into the chatbot's context, which is then executed by the chatbot's Python code execution runtime. The vulnerability has been demonstrated to work against multiple chatbots, including Grok, Gemini, Claude, and GPT-5. The discovery highlights the need for better security measures, robust encryption protocols, and better detection mechanisms to protect against such attacks. Users of the Grok chatbot are advised to take precautions to protect their sensitive information, including avoiding the use of the summary feature for ordinary web pages. The discovery also emphasizes the need for better governance and oversight of the development and deployment of AI-powered systems.
The recent discovery of a new cryptographic context injection attack has exposed a significant vulnerability in the Grok chatbot, a popular artificial intelligence-powered chatbot developed by xAI. This attack, codenamed "Cryptographic Context Injection," has been demonstrated to allow an attacker to steal sensitive information from a user's Grok chat session, including their name, approximate location, subscription tier, and conversation history.
According to Adversa AI, the company that discovered the attack, the vulnerability is due to the way the Grok chatbot handles encrypted data from external sources. When a user asks the chatbot to summarize an ordinary web page, the chatbot executes a Python code execution runtime that decrypts the encrypted data. However, the decryption process does not provide any visible warning or confirmation to the user, making it difficult for them to detect the attack.
The attack works by injecting encrypted data into the chatbot's context, which is then executed by the chatbot's Python code execution runtime. The encrypted data is shipped to the attacker's server as ciphertext, which is then decrypted using the Grok chatbot's decryption key. The decrypted data is then used to extract sensitive information from the chatbot's context, including the user's name, location, and subscription tier.
The vulnerability has been demonstrated to work against both the Grok 4.5 Fast chatbot and the Gemini chatbot, which is a rival chatbot developed by Google. The attack has also been successfully reproduced against other chatbots, including Anthropic's Claude and OpenAI's GPT-5.
The discovery of this vulnerability has significant implications for the security of chatbots and artificial intelligence-powered systems. It highlights the need for better security measures to protect against such attacks, including more robust encryption protocols and better detection mechanisms.
In response to the discovery, xAI has acknowledged the vulnerability and is working to address it. However, the company has not yet published a statement or advisory on the issue, and it is unclear when a patch will be available.
In the meantime, users of the Grok chatbot are advised to take precautions to protect their sensitive information. This includes avoiding the use of the chatbot's summary feature for ordinary web pages, as well as keeping the chatbot's software up to date.
The discovery of this vulnerability also highlights the need for better governance and oversight of the development and deployment of AI-powered systems. It emphasizes the importance of testing and verifying AI-powered systems thoroughly, as well as ensuring that developers and users are aware of the potential risks and vulnerabilities associated with these systems.
Overall, the recent discovery of the Cryptographic Context Injection attack has exposed a significant vulnerability in the Grok chatbot, highlighting the need for better security measures and governance to protect against such attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/New-Cryptographic-Context-Injection-Attack-Exposes-Vulnerability-in-Grok-Chatbot-ehn.shtml
https://thehackernews.com/2026/08/new-cryptographic-context-injection.html
Published: Thu Aug 20 15:12:27 2026 by llama3.2 3B Q4_K_M