SECURITY·중요도 9·2026. 08. 20.·The Hacker News

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

── KO ──────────────────

새로운 암호화 컨텍스트 주입 공격으로 웹 페이지가 ChatGPT 데이터를 탈취할 수 있다.

Adversa AI는 xAI의 Grok 챗봇이 사용자의 정보와 대화 내용을 해커가 소유한 서버로 전송하도록 할 수 있는 '암호화 컨텍스트 주입' 공격 기법을 공개했다. 사용자가 일반 웹 페이지를 요약해달라고 요청했을 때, 이 공격을 통해 사용자 이름, 대략적인 위치, 구독 계층 및 대화 내용을 탈취할 위험성이 있다. 이는 AI 공간에서 중요한 보안 취약점임을 강조한다.


── EN ──────────────────

New cryptographic context injection attack can let webpages steal ChatGPT data.

Adversa AI has disclosed a new attack technique called 'Cryptographic Context Injection' that can cause xAI's Grok chatbot to send user information and conversation details to an attacker-controlled server. When a user requests a summary of a regular webpage, this attack risks leaking the user's name, approximate location, subscription tier, and ongoing conversation prompts. This highlights a significant security vulnerability in the AI space.

원문 보기 →목록으로