According to Cryptopolitan, cybersecurity company Adversa AI has disclosed an encrypted context injection vulnerability in xAI's AI assistant Grok. Attackers can hide encrypted commands on web pages, which Grok executes while summarizing the page, sending user names, geographic locations, subscription levels, and chat records to the attackers' servers. The vulnerability was reported to xAI via the HackerOne platform on June 3, 2026. Researcher Rony Utevsky followed up on August 4 and August 10, but as of August 19, the vulnerability on (Grok.com) remains unpatched, and xAI has not provided a timeline for the fix.