[{"data":1,"prerenderedAt":30},["ShallowReactive",2],{"nr-en-grok-zero-click-chat-history-theft-vulnerability":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":22,"trackerLabel":23,"headlineStat":24,"image":25,"ogImage":26,"imageAlt":5,"csv":10,"minutes":27,"words":28,"html":29},"grok-zero-click-chat-history-theft-vulnerability","Grok Security Flaw: Zero-Click Attack Steals Chat History","Researchers at Adversa AI have demonstrated a new attack technique that compromises xAI's Grok without requiring user interaction. The method uses AES encryption to bypass AI safety guardrails.","2026-08-24","08:01","2026-08-24T08:01:00+02:00","","August 24, 2026","news","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"AI Security","Prompt Injection","Grok","Adversa AI","Data Privacy","\u002Ftools\u002Fki-durchsetzungsmonitor","AI Security Incidents","Zero-click attack steals complete chat history","\u002Fnewsroom\u002Fimg\u002Fgrok-zero-click-chat-history-theft-vulnerability.webp","\u002Fog-nr\u002Fgrok-zero-click-chat-history-theft-vulnerability.en.png",3,504,"\u003Cp>Security researcher Rony Utevsky from Adversa AI has developed a new attack technique called \u003Cstrong>Cryptographic Context Injection\u003C\u002Fstrong> that bypasses AI safety filters through encrypted payloads. According to the report, the method was demonstrated against two live production systems: \u003Cstrong>xAI&#39;s Grok\u003C\u002Fstrong> and \u003Cstrong>Google&#39;s Gemini\u003C\u002Fstrong>. For Grok, the security vulnerability is particularly critical – an attacker can steal a user&#39;s complete chat history without requiring any user interaction.\u003C\u002Fp>\n\u003Ch2>Key Facts\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Attack targets:\u003C\u002Fstrong> xAI&#39;s Grok and Google&#39;s Gemini; Grok vulnerability rated as more severe\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Technique:\u003C\u002Fstrong> AES-256-GCM encryption hides instructions from content filters; the model decrypts the payload within its own sandbox\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data theft:\u003C\u002Fstrong> Access to \u003Cstrong>username, location, subscription status, and full chat history\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Distinguishing feature:\u003C\u002Fstrong> Zero-click – no user interaction required, no warning displayed\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>How the Attack Works\u003C\u002Fh2>\n\u003Cp>The mechanism is deceptively simple: A user is asked to summarize a webpage containing an encrypted payload. Grok visits the page, decrypts the AES-256-GCM payload in its Python sandbox, and executes the hidden instructions within. The system then accesses the user&#39;s private session data – including name, location, subscription plan, and complete chat history – and automatically opens a URL containing this information. The user remains unaware of the entire process.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>&quot;Cryptographic Context Injection hides malicious instructions inside AES-encrypted text so guardrails can&#39;t read them, then tricks the AI into decrypting and trusting them as its own,&quot; states the Adversa AI report.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch2>Why Existing Security Measures Fail\u003C\u002Fh2>\n\u003Cp>The critical technical distinction from earlier cipher-based prompt injection attacks lies in the decryption process itself. Static security guardrails classify inputs as text – they do not execute them. An attacker ships ciphertext along with key material and a decryption instruction. The model then runs the decryption within its own code execution sandbox.\u003C\u002Fp>\n\u003Cp>Earlier techniques such as \u003Cstrong>CipherChat\u003C\u002Fstrong> and \u003Cstrong>CodeChameleon\u003C\u002Fstrong> used substitution ciphers, XOR, or Base64 – schemes the model can decode natively within its context. \u003Cstrong>AES-256-GCM\u003C\u002Fstrong> operates differently: decryption requires a runtime interpreter that no standard content classifier executes during inspection. This gap is precisely what the attack exploits.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>&quot;The runtime execution launders attacker-controlled data into trusted instructions the agent will act upon. That is how the attack got its name: cryptography helps fabricate trusted context for the agent.&quot;\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>The result: stolen data is concealed behind an innocuous request – such as &quot;summarize this page&quot; – and the payload inherits credibility it would never possess if inserted directly into the prompt.\u003C\u002Fp>\n\u003Ch2>Implications for Decision-Makers\u003C\u002Fh2>\n\u003Cp>This vulnerability demonstrates that even advanced AI systems in production environments remain susceptible to novel attack classes. For organizations evaluating or deploying Grok or similar frontier models, this is a clear signal: security audits must extend beyond standard prompt injection. The ability of a model to execute code – a feature for productivity – becomes an attack vector here. Organizations should clarify how their AI systems handle encrypted content and whether user data is truly isolated.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fsecurityaffairs.com\u002F197717\u002Fhacking\u002Fzero-click-grok-chat-history-theft-adversa-ai-demonstrates-cryptographic-context-injection.html\">Security Affairs\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1787554135630]