Security researchers disclosed a technique called Cryptographic Context Injection in which an ordinary web page embeds an encrypted payload and decryption instructions; when a user asks xAI’s Grok to summarize that page, the chatbot decrypts and executes the hidden instructions inside its own code-execution sandbox. The instructions can then silently exfiltrate the user’s name, approximate location, subscription tier, and chat history to an attacker-controlled server with no click or warning required. The flaw was first reported to xAI in June 2026 and remained unpatched at public disclosure in August 2026, with roughly a 40% success rate across repeated tests; related, lower-success variants were also found to affect other vendors’ chatbots.