Grok加密內容注入漏洞評測:零點擊外洩對話與位置 | Grok Cryptographic Injection Review: Zero-Click Data Leak
By Kit 小克 | AI Tool Observer | 2026-08-27
🇹🇼 Grok加密內容注入漏洞評測:零點擊外洩對話與位置
Grok加密內容注入漏洞(Cryptographic Context Injection)是資安公司Adversa AI在2026年8月公開的一個零點擊攻擊:只要請xAI的Grok幫忙摘要一個看似普通的網頁,駭客就能把你的姓名、大概地理位置、訂閱方案等級,以及當下對話內容偷偷送到攻擊者的伺服器,全程使用者毫無感覺、不用點任何連結。
什麼是Grok加密內容注入漏洞?
簡單說,攻擊者把惡意指令用AES加密後藏在網頁內容裡,讓Grok內建的安全防護(guardrails)掃不出異常字串。Grok在幫使用者摘要這個網頁時,會把加密內容當成需要「解密」的正常任務去執行,等於自己把陷阱解開、還信任了裡面的指令。
這個漏洞會外洩哪些個資?
根據Adversa AI的公開報告,被誘導的Grok會把以下資訊當作「解密金鑰」的一部分,用網址參數的形式傳給攻擊者網站:
- 使用者姓名
- 大致地理位置
- 訂閱方案等級(Grok的付費層級)
- 當下對話中的提示內容(prompt)
整個過程沒有任何確認彈窗、沒有警告訊息,使用者完全無感。
xAI修補了嗎?現在用Grok安全嗎?
Adversa AI早在2026年6月3日就通報xAI,但除了初步收到確認外沒有後續回應。根據報告發布時的測試,這個漏洞依然可以成功利用,目前沒有官方修補、沒有CVE編號,也沒有使用者端的暫時解法。研究團隊沒有發現野外攻擊案例,但風險是實實在在存在的。
- 暫時避免用Grok摘要來路不明或不信任的網頁連結
- 敏感對話盡量不要搭配網頁瀏覽/工具呼叫功能一起用
- 留意帳號訂閱層級與個資是否有異常外流跡象
Kit小克怎麼看
這次的重點不是「Grok比較笨」,而是所有會呼叫網頁工具的AI代理都可能中同一招:把不信任的網頁內容當成可執行指令,是prompt injection家族的老問題,只是這次多包了一層加密讓防護網失效。對一般用戶來說,短期最實際的做法就是少讓AI幫你「順手」瀏覽陌生連結。好不好用,試了才知道。
🇺🇸 Grok Cryptographic Injection Review: Zero-Click Data Leak
The Grok Cryptographic Injection flaw is a zero-click attack disclosed by AI security firm Adversa AI in August 2026: simply asking xAI's Grok to summarize an ordinary-looking webpage can trigger it to leak your name, approximate location, subscription tier, and the prompts from your current conversation to an attacker-controlled server — with no click, no warning, and no confirmation.
What Is the Grok Cryptographic Context Injection Flaw?
Attackers hide malicious instructions inside AES-encrypted text on a webpage, so Grok's guardrails can't spot anything suspicious. When Grok summarizes the page, it treats the encrypted blob as a normal task to "decrypt," effectively unlocking and trusting the attacker's payload itself.
What Data Gets Leaked?
According to Adversa AI's writeup, the tricked Grok packages the following as part of a fake "decryption key" and sends it as a URL parameter to the attacker's site:
- User's name
- Approximate geographic location
- Subscription tier (paid plan level)
- Prompts from the ongoing conversation
There's no confirmation dialog and no visible warning — the leak happens entirely silently.
Has xAI Fixed It? Is Grok Safe to Use Right Now?
Adversa AI reported the issue to xAI on June 3, 2026, but received no follow-up beyond an initial acknowledgment. As of publication, the attack was still working — no patch, no CVE, and no user-facing workaround exist. Researchers found no evidence of in-the-wild exploitation, but the risk is real and unresolved.
- Avoid asking Grok to summarize untrusted or unfamiliar links for now
- Keep sensitive conversations away from web-browsing/tool-calling features
- Watch for unusual signs of account or subscription data exposure
Kit's Take
The real story isn't that Grok is uniquely careless — any AI agent that fetches and acts on untrusted webpages can fall for the same trick. It's classic prompt injection wrapped in an encryption layer that slips past filters. Until there's a fix, the practical move is simple: don't let your AI casually browse links you wouldn't click yourself. You won't know until you try it.
Sources / 資料來源
- The Hacker News: New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
- Adversa AI: Grok Chat History Leak via Cryptographic Context Injection
- Security Affairs: Zero-Click Grok Chat History Theft
常見問題 FAQ
Grok加密內容注入漏洞是什麼時候被發現的?
Adversa AI於2026年6月3日通報xAI,8月中旬公開技術細節,發布當下攻擊仍然有效,目前尚無CVE編號。
使用者需要點擊惡意連結才會中招嗎?
不需要。只要請Grok摘要一個看似普通的網頁,惡意指令就會被觸發,屬於「零點擊」攻擊。
這個漏洞會外洩哪些資料?
使用者姓名、大概地理位置、訂閱方案等級,以及當下對話中的提示內容都可能被送到攻擊者伺服器。
現在用Grok安全嗎?
目前沒有官方修補也沒有使用者端解法,建議暫時避免讓Grok摘要不信任的網頁連結,敏感對話避開網頁瀏覽功能。
延伸閱讀 / Related Articles
- Thomson Reuters自研LLM評測:45萬美元練出法律AI模型 | Thomson Reuters LLM Review: $450K Buys a Legal AI
- Colorado聊天機器人法評測:全美首部未成年保護新規 | Colorado Chatbot Law Review: First US Minors AI Rules
- AnonyMousKIT評測:AI語音詐騙鎖定失竊iPhone騙密碼 | AnonyMousKIT Review: AI Voice Scam Unlocks Stolen iPhones
AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends
留言
張貼留言