Brave published details about a security issue with Comet, Perplexity’s AI browser, that enables an attacker to inject a prompt into the browser and gain access to data in other open browser tabs.
Comet AI Browser Vulnerability
Brave described a vulnerability that can be activated when a user asks the Comet AI browser to summarize a web page. The LLM will read the web page, including any embedded prompts that command the LLM to take action on any open tabs
According to Brave:
“The vulnerability we’re discussing in this post lies in how Comet…








