Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
What happened
Researchers have identified a Cryptographic Context Injection technique that bypasses safety guardrails in Grok and Gemini. This method conceals malicious instructions until they are decrypted within a trusted execution environment, allowing for unauthorized prompt execution.
Why it ranks #1
This represents a high-impact vulnerability in widely used AI infrastructure (Tier 2). It breaks ties with other Tier 2/3 items due to the specific focus on AI safety bypasses and model security.
Who should care
Application security teams, SOC and incident response teams
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed