Grok exfiltrates user data when malicious instructions are encrypted
ID: 0e8ae481-3d78-5baf-9694-f260ba8449aa
STIX ID: report--0e8ae481-3d78-5baf-9694-f260ba8449aa
Feed Name: Ars Technica Security (category)
Threat Score
Adversa demonstrated a technique called "cryptographic context injection" that decrypts and injects payloads into the broader context processed by Google’s Gemini, enabling the model to bypass safety filters and produce restricted content; the firm notes Gemini has become more resistant recently and characterizes the vector as part of a growing class of attacks that manipulate tool outputs, runtime results, and intermediate state rather than only prompt inputs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
