“The attack requires no exploits, no user clicks, and no explicit requests for sensitive actions”: Experts say Perplexity’s AI Comet browser can be hacked to steal your passwords.


  • Zenity researchers discovered PleaseFixa non-click indirect prompt injection flaw in Comet browser
  • Malicious calendar invites could trick AI into exfiltrating passwords and sensitive files without the user’s knowledge.
  • Bug fixed with restrictions on access to file://, preventing agents from reading the local file system

Perplexity’s AI-powered Comet web browser is vulnerable to indirect rapid injection attacks, which malicious actors can exploit to exfiltrate sensitive data such as passwords, experts have warned.

Security researchers Zenity dubbed the flaw PleaseFix and demonstrated various ways to abuse it.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top