xAI’s AI assistant Grok has a security flaw known as cryptographic context injection, according to cybersecurity company Adversa AI as reported by Cryptopolitan and cited by ChainCatcher. Attackers can conceal cryptographic commands in ordinary webpages; when users ask Grok to summarize those pages, the assistant may automatically decrypt and execute the commands. The data sent to an attacker-controlled server can include the user’s name, geographic location, subscription level and complete chat history. Researcher Rony Utevsky reported the vulnerability to xAI through HackerOne on June 3, 2026, and followed up on Aug. 4 and Aug. 10. As of Aug. 19, the issue had not been fixed on Grok.com, and xAI had not provided a patch timeline.