New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Summary
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.