logo

Grok exfiltrates user data when malicious instructions are encrypted

ID: 0e8ae481-3d78-5baf-9694-f260ba8449aa

STIX ID: report--0e8ae481-3d78-5baf-9694-f260ba8449aa

Feed Name: Ars Technica Security (category)

Threat Score
35/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Dan Goodin

...
...

Adversa demonstrated a technique called "cryptographic context injection" that decrypts and injects payloads into the broader context processed by Google’s Gemini, enabling the model to bypass safety filters and produce restricted content; the firm notes Gemini has become more resistant recently and characterizes the vector as part of a growing class of attacks that manipulate tool outputs, runtime results, and intermediate state rather than only prompt inputs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.