Grok Hit by Password Context Injection Attack: Zero-Click Chat History Exfiltration, xAI Unpatched for Two Months
Security firm Adversa AI disclosed on August 20, 2026, that xAI's Grok 4.5 Fast in the grok.com web chat is vulnerable to a "password context injection" attack. When users request summaries of ordinary web pages, their name, location, subscription tier, and current conversation history can be sent to an attacker's server without any prompt or visible warning.