SECURITYMALWAREBYTES LABS
Grok fooled into stealing user chat, location data, and more
A new attack technique called “Cryptographic Context Injection” allows malicious instructions to be hidden within encrypted data, bypassing AI guardrails. This method tricks the AI into decrypting the malicious content using its own code-execution tools, which may cause it to treat the resulting text as trustworthy internal information. Researchers tested this against Grok, showing it could steal user chat and location data, and Gemini, demonstrating restricted content generation.
Mentioned
Related Signal