Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Attack Exploits Grok Chat to Leak User Data

New Attack Exploits Grok Chat to Leak User Data

Posted on August 20, 2026 By CWS

Adversa AI has unveiled a novel attack method capable of compromising xAI’s Grok chatbot, allowing it to secretly transmit user-specific information such as names, locations, subscription levels, and chat prompts to a server managed by an attacker. This occurs when the chatbot is tasked with summarizing a typical web page.

The method, termed ‘Cryptographic Context Injection’ by the AI security firm, demonstrates how this data transfer can occur without any confirmation step or visible alert to the user as proven in their demonstration.

Unpatched Vulnerability Details

Currently, there is no available fix or workaround for this vulnerability, nor is there a CVE identifier assigned. Adversa AI reported that they tested the Grok web chat version 4.5 Fast on August 19, 2026, and successfully reproduced the attack. The company has noted a 40% success rate from 20 attempts since June, with failures attributed to Grok’s decryption struggles rather than any detection of the exploit.

The attack involves sending encrypted instructions to the chatbot, which decrypts them using its internal Python execution environment. This process bypasses content classifiers because they cannot interpret strong encryption, thus allowing the instructions to be executed as Grok processes the code.

The Attack Mechanism

The decrypted instructions prompt the chatbot to compile private session data into a URL. This URL is then accessed by Grok, embedding user data in its query parameters. The security flaw arises from Grok’s ability to process external instructions without proper checks, allowing attackers to exploit this path undetected.

Adversa AI’s lead researcher, Rony Utevsky, highlighted the challenge of detecting such attacks due to the lack of effective boundaries or consent mechanisms within the framework, which permits data laundering from untrusted sources to privileged tools.

Industry Reactions and Future Implications

Adversa AI disclosed this issue to xAI and their HackerOne bug bounty platform on June 3, 2026, but received no detailed response or mitigation timeline. The lack of a public statement from xAI further complicates the situation as of August 20, 2026.

A separate demonstration involving Google’s Gemini model was also reported, showing similar vulnerabilities. However, Google was not notified because jailbreaks fall outside the scope of Adversa AI’s disclosure program. The attack’s success rate against Gemini has decreased, possibly due to updates in filter settings or model versions.

The findings underscore the need for AI developers to enhance security measures, particularly in managing how agents execute instructions and interact with external data. Recommendations include isolating untrusted content, ensuring irreversible actions are gated, and maintaining logs for audit and forensic purposes.

These developments emphasize the ongoing challenge of securing AI systems from sophisticated attacks, necessitating rigorous oversight and proactive measures to protect user data.

The Hacker News Tags:Adversa AI, AI vulnerability, API security, chat security, Chatbot, Cryptographic Context Injection, Cybersecurity, data leak, Encryption, Gemini, Grok, HackerOne, prompt injection, user privacy, xAI

Post navigation

Previous Post: ToxicPanda Malware Threatens Android Users with PIN Theft
Next Post: Understanding Modern Surveillance: Key Insights and Concerns

Related Posts

FIRESTARTER Backdoor Threatens Cisco Devices Despite Patches FIRESTARTER Backdoor Threatens Cisco Devices Despite Patches The Hacker News
IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass The Hacker News
Fake Facebook Offers Exploit Users in MENA Region Fake Facebook Offers Exploit Users in MENA Region The Hacker News
OpenSSL Vulnerability Causes Memory Freeze with Minimal Data OpenSSL Vulnerability Causes Memory Freeze with Minimal Data The Hacker News
Newly Patched Critical Microsoft WSUS Flaw Comes Under Active Exploitation Newly Patched Critical Microsoft WSUS Flaw Comes Under Active Exploitation The Hacker News
USB Exploit Enables SYSTEM Access on Windows 11 USB Exploit Enables SYSTEM Access on Windows 11 The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark