logo

Grok Zero-Click Attack: Critical Data Theft Risk

ID: cda94607-1de9-5a78-9f16-4c72fc6cc825

STIX ID: report--cda94607-1de9-5a78-9f16-4c72fc6cc825

Feed Name: CyberNexora News

Threat Score
55/100

Date Published: 2026-08-22

Date Updated: 2026-08-22

Author: Debolina Barik

...
...

**Grok Zero-Click Attack:** Researchers disclosed a cryptographic prompt injection technique where encrypted instructions embedded in webpages are decrypted by an AI agent (Grok), potentially causing the agent to treat the decrypted content as trusted tool output and exfiltrate session data (user name, coarse location, subscription tier, conversation content) via browsing capabilities; the technique was reproducible in tests (~40% success) but had no reported CVE or confirmed real-world exploitation at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.