# Researcher reports Grok web-chat data-exfiltration technique

_Tuesday, August 18, 2026 at 8:00 PM EDT · Security · Developing · Tier 1 — Major_

![Researcher reports Grok web-chat data-exfiltration technique — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPv76ODDXuPeov3fu_Gs_V-72pKnjw38Qu9A4qXOn_2QFd9daTYFAXre2eubEQ6Fwb65SwXgv10mhyDCGE_KcvL69c-CGe2BfEiOj74UTHwv6WAhMyxNuVGOEdUZYwz0Y9v55SFmaOwjHQYHbOyzvZEofi0egkTfeFxQlJRD3Sj6ve-TZ47SM1sNfYGB0/s1700-e365/grok-chat.jpg)

Adversa AI reported that a crafted web page could cause Grok web chat to send a user's name, approximate location, subscription tier and current-chat prompts to an attacker-controlled server. The company said it reproduced the technique once on Grok 4.5 Fast on August 19, using encrypted instructions that Grok decrypted in its Python runtime before invoking a navigation tool. xAI had not published an advisory.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/new-cryptographic-context-injection.html)

---
Canonical: https://techandbusiness.org/newswire/iWrLKa8Nz4QQaboV7dMkHf
Retrieved: 2026-08-20T21:08:45.768Z
Publisher: Tech & Business (techandbusiness.org)
