Security researchers have demonstrated a new prompt-injection attack against xAI's Grok, similar to one recently shown targeting Microsoft 365 Copilot. By embedding malicious instructions in encrypted content, the attackers can make Grok exfiltrate user chats and other personal information.
The researchers notified xAI in June, but the vulnerability remained exploitable when the report was published. The incident highlights that large language models cannot solve the root cause of prompt injections; developers must rely on guardrails to prevent harmful actions.
Comments