Perplexity’s Comet AI Browser May Have Concerning Security Vulnerabilities That Could Allow a Hacker to Hack Your Device


  • SquareX Discovered MCP API Hidden in Comet Browser Allowing Execution of Arbitrary Local Commands
  • A vulnerability in the Agentic extension could allow attackers to hack devices via the compromised perplexity.ai site.
  • The demo showed WannaCry running; Researchers warn that third-party catastrophic risk is inevitable

Cybersecurity experts at SquareX say they have found a major vulnerability in Comet, the AI ​​browser built by Perplexity, that could allow malicious actors to take full control of the victim’s device.

SquareX discovered that the browser has a hidden API capable of executing local commands (commands on the underlying operating system, as opposed to just the browser).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top