Flash News
Adversa AI revealed a gap in Grok and the risk of leaking user data
According to Cryptopolitan, the network security company Adversa AI disclosed that XAI-Ai ' s assistant Grok had an encrypted context leaking. The assailant can hide the encrypted command on the web page, and when Grok summarizes the page, executes the command and sends the user ' s name, geographic location, subscription level and chat record to the attacker ' s server. The loophole was disclosed to XAI through the HackerOne platform on 3 June 2026, followed up by Researcher Rony Utevsky on 4 and 10 August, respectively, and the Grok.com gap remained unrepaired as at 19 August, and XAI did not provide a schedule for patches。
