AI agents that can browse the Web and perform tasks on your behalf have incredible potential but also introduce new security risks.
We recently found, and disclosed, a concerning flaw in Perplexity's Comet browser that put users' accounts and other sensitive info in danger.
Aug 20, 2025 · 1:01 PM UTC
94
563
3,873
1,552,909
This security flaw stems from how Comet summarizes websites for users.
When processing a site's content, Comet can't tell content on the website apart from legitimate instructions by the user. This means that the browser will follow commands hidden on the site by an attacker.
2
25
555
59,222
These malicious instructions could be white text on a white background or HTML comments. Or they could be a social media post.
If Comet sees the commands while summarizing, it will follow them even if they could hurt the user. This is an example of an indirect prompt injection.
1
16
413
42,893
One example attack:
1. A Comet user sees a Reddit thread where one comment has hidden instructions.
2. The user asks Comet to summarize the thread.
3. Comet follows the malicious instructions to find the user's Perplexity login details and send them to the attacker.
7
72
728
52,680
This attack demonstrates the risks presented by AI agents operating with full user authentication across multiple sites.
New security measures are needed to make agentic browsing safe.
1
9
363
31,475
In today's blog post, we share more details on this vulnerability and discuss potential protections against other attacks of this nature.
Perplexity has patched this error since we reported it to them. brave.com/blog/comet-prompt-…
3
25
316
38,165