AI agents that can browse the Web and perform tasks on your behalf have incredible potential but also introduce new security risks. We recently found, and disclosed, a concerning flaw in Perplexity's Comet browser that put users' accounts and other sensitive info in danger.

Aug 20, 2025 · 1:01 PM UTC

94
563
3,873
1,552,909
This security flaw stems from how Comet summarizes websites for users. When processing a site's content, Comet can't tell content on the website apart from legitimate instructions by the user. This means that the browser will follow commands hidden on the site by an attacker.
2
25
555
59,222
These malicious instructions could be white text on a white background or HTML comments. Or they could be a social media post. If Comet sees the commands while summarizing, it will follow them even if they could hurt the user. This is an example of an indirect prompt injection.
1
16
413
42,893
One example attack: 1. A Comet user sees a Reddit thread where one comment has hidden instructions. 2. The user asks Comet to summarize the thread. 3. Comet follows the malicious instructions to find the user's Perplexity login details and send them to the attacker.
7
72
728
52,680
This attack demonstrates the risks presented by AI agents operating with full user authentication across multiple sites. New security measures are needed to make agentic browsing safe.
1
9
363
31,475
In today's blog post, we share more details on this vulnerability and discuss potential protections against other attacks of this nature. Perplexity has patched this error since we reported it to them. brave.com/blog/comet-prompt-…
3
25
316
38,165
Security and privacy cannot be an afterthought in the race to build more capable AI tools. In the next blog post of this series, we'll discuss Brave's efforts to deliver secure AI browsing to our nearly 100 million users. Stay tuned!
3
14
296
33,395
This was only an issue within Comet. Dia doesn’t have the agentic capabilities that make this attack possible.
1
1
120
12,404
No need to tag. We notified them as soon as we found the vulnerability last month.
4
380
19,237
Replying to @brave
is brave going to make itself agentic ? you could charge a subscription for it
2
4
6,113
We’re working on agentic AI and will have another blog soon about how we’re making it secure.
4
58
5,757
Replying to @brave
Shouldn’t at least the problem in the example be easily preventable by stricter and more detailed rules and training for the ai agent including security features like the ranking of information by confidentiality and having different safety layers with different requirements?
1
3
15,733
Yes, one of our recommendations is having stricter controls for sensitive tasks. For example, the browser should be asking for user consent before sending an email. Today's blog has a few more recommendations: brave.com/blog/comet-prompt-…
1
51
13,944
Replying to @brave
I’m asking nearly a year now will Ireland be added to the news dropdown box on brave search engine? The one I have to pick is uk as USA is not news that I want, I want Irish news
1
2
5,802
Hi, the team saw one of your previous tweets on this and is discussing it. Thank you for the feedback!
1
14
4,753
Replying to @brave
yikes
5
3,056
Replying to @brave
Yikes!
3
1,186
Replying to @brave
Replying to @koltregaskes
But how... its a just input? We can add xml tags or special delimiters, but really there is no getting around this problem with current models. It's all just input. simonwillison.net/2025/Jun/1…
2
1,278
Replying to @brave
we really need to change the api of llms to more concretely specify between trusted and untrusted input...
2
2,476
Replying to @brave
Brave is awesome. I wish there were more customizations to make the UX minimal. For eg. Autohiding the top bar would be nice.
13
6,184
Replying to @brave
Watch out they are going to pretend to buy you
1
13
4,885
Replying to @brave
Brave out here doing Gods work.
6
1,607
Replying to @brave
Good catch, Brave! 🤝
3
1,872
Replying to @brave
We did something similar way earlier nitter.catsarch.com/aryamanTitan/status/19…
We broke @PerplexityComet, it's vulnerable to indirect prompt injection! When asked to summarize a webpage, it unsuspectingly 1) Closes all the other tabs 2) Opens random tabs overwhelming the user (watch with Sound ON 🔊)
3
120