logo

Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

ID: f458e9e9-1582-5d61-896d-5f868b3c4573

STIX ID: report--f458e9e9-1582-5d61-896d-5f868b3c4573

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-08-23

Date Updated: 2026-08-23

Author: Pierluigi Paganini

...
...

Adversa AI demonstrated a new attack named Cryptographic Context Injection in which AES-encrypted ciphertext and key material on a webpage are decrypted inside a model's code-execution sandbox, laundering attacker instructions into trusted agent context; this enabled zero-click theft of xAI Grok chat histories and safety-policy bypasses in Google Gemini. The root cause is the agent/harness design that allows untrusted content to invoke privileged tools, network calls, and access session metadata without explicit egress controls or consent, and the researcher recommends treating untrusted content in isolated contexts, requiring resolved-argument confirmation for outbound actions, and logging per-session tool traces for detection and forensics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.