the news now

The world's news, cross-checked among reputable sources.

This is a new development in a story we have covered before · earlier coverage

Security Researchers Discover Cryptographic Prompt Injection Vulnerability in Grok

2 sources across 2 countries · United Kingdom · United States

Who reported this

  • The Register United Kingdom · Centre · Situation Publishing Ltd
  • Ars Technica United States · Centre · Conde Nast (Advance Publications)

What the colours mean

  • Left
  • Centre-left
  • Centre
  • Centre-right
  • Right
  • A hatched block means the outlet is affiliated with, or controlled by, a state.

Political lean describes where an outlet sits within the politics of its own country. It is never a position on a single global scale.

Political lean is comparable inside one country and not across them, which is why the bar groups by country first. Publicly funded broadcasters are not marked as state-linked.

The owner of each outlet is listed as a matter of record, not as a judgement about the outlet.

Every outlet covering this story shares the same political lean; read with that in mind.

Security researchers at Adversa AI have identified a novel vulnerability in xAI's Grok web chat agent called cryptographic context injection. This technique allows attackers to bypass AI guardrails by placing encrypted malicious instructions and a decryption key on a web page. While standard input filters cannot read the encrypted text, the AI model uses its code execution sandbox to decrypt the instructions and then carries them out. In a proof of concept demo, the attack was used to exfiltrate a victim's chat history, including their name, coarse location, subscription tier, and full conversation prompts, by appending them to a URL.

Lead researcher Rony Utevsky reported that xAI was informed of the vulnerability on June 3, 2026, through direct contact and the HackerOne bug bounty program. Although xAI acknowledged the report, it did not provide a mitigation timeline, and the technique reportedly still worked on Grok.com as of August 19. SpaceX, which acquired xAI earlier this year, did not respond to requests for comment.

Adversa also tested the method on Google's Gemini. While Gemini's lack of external website access for Python prevented the same data exfiltration scenario seen with Grok, researchers were able to use the technique to bypass safety filters and generate instructions for building an incendiary weapon. Google was not informed of the attack because the company considers jailbreaks to be out of scope for its vulnerability disclosure program. Utevsky noted that the success rate against Gemini declined significantly by August, which may be due to model version changes or filter updates.

How each side framed it

Centre
Both center leaning outlets focused on the technical mechanics of the vulnerability and the failure of AI developers to address the root causes of prompt injection.

Sources

100% of the statements in this article were traced back to the source articles listed above.