wire / 2026-08-20-1549
Adversa AI finds unpatched Grok flaw that decrypts hidden malicious instructions from web pages
Grok reads a page, quietly decrypts the attacker's instructions, and mails your chat history home. The patch is still pending.
The facts
Security researchers at Adversa AI discovered a vulnerability in xAI's Grok chatbot that allows attackers to embed encrypted malicious instructions in web content. When Grok processes such content, it decrypts and executes the hidden commands, leaking users' private data—including names, locations, and chat histories—to attackers. The flaw remains unpatched.