"Summarise this page" was enough to hand over a chatbot conversation
Ask a chatbot to summarise a web page and you'd assume the worst outcome is a bad summary. Adversa AI spent the summer demonstrating otherwise, and as of last week the problem was still live.
They call it Cryptographic Context Injection, and the shape of it is neat enough to be worth understanding. An attacker puts two things on a web page: a block of genuinely encrypted text, and the instructions for unlocking it. Any filter scanning that page for malicious prompts sees gibberish, because at that stage it really is gibberish. Then somebody asks Grok to summarise the page. Grok fetches it, uses its own code-running tool to decrypt the block - the page helpfully explains how - and then treats what comes out as instructions to obey rather than as text it happened to read on a website. In the researchers' tests, what it did next was send the user's name, approximate location, subscription tier and every prompt from the conversation so far to a server they controlled, tucked into the end of a web address. No click involved, and nothing on screen to see.
Adversa reported it to xAI and HackerOne on 3 June, chased twice in August, and confirmed on 19 August that it still worked, succeeding roughly two attempts in five. The same technique got Google's Gemini to produce material its safety filters normally block, although that has become harder since June.
The useful takeaway isn't about Grok specifically. A chatbot that can browse the web and run code isn't a neutral reader, so "summarise this link for me" from a stranger deserves the same suspicion as any other link from a stranger. And keep passwords, card numbers and recovery codes out of these conversations entirely, because everything in the conversation is in scope. On the Windows side, Tendvane's Privacy and accounts check shows what your sign-in on the PC actually exposes.