logo

Grok fooled into stealing user chat, location data, and more

ID: 9e32a88b-ac6f-5c6a-8b09-978985e9c95f

STIX ID: report--9e32a88b-ac6f-5c6a-8b09-978985e9c95f

Feed Name: Malwarebytes Blog

Threat Score
60/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

...
...

Researchers identified a new prompt-injection attack called "Cryptographic Context Injection" that conceals malicious instructions inside encrypted payloads; AI agents that are given code-execution or browsing capabilities can be tricked into decrypting and executing those instructions, allowing guardrails to be bypassed and sensitive data or restricted content to be exposed. The technique was tested against production systems (Grok and Gemini) with differing results, and the report urges caution with AI assistants that have access to browsers, code tools, or private data while providing practical mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.