Perplexity's AI Comet browser warned of a serious security vulnerability

Cát Tiên (THEO indianexpress) |

Perplexity's AI Comet browser was warned by Brave of a serious vulnerability, with the risk of being exploited by attackers to steal sensitive data.

Security researchers have just warned that Perplexity's AI Comet browser has a vulnerability that can be exploited by attackers to steal users' sensitive data, including email, banking password and personal information.

According to the announcement from the research team at Brave (a privacy-focused browser developer in the US), the vulnerability comes from Comet's way of handling web content when performing commands such as "shortening this website".

browser cannot distinguish between valid requirements from users and unreliable content. This allows attackers to dilate malicious directives into the website, turning them into orders that Comet automatically executes.

For example, an attacker can hide a request for user email access in an invisible text section on another tab, Brave wrote in the report.

Hacious instructions can appear as whiteboards on white background, HTML comments or even inserted into social media posts like Reddit or Facebook.

Brave believes that this vulnerability is particularly dangerous because Comet is considered the first AI browser to bring AI agents to the search experience center, with direct access to data from platforms that users have logged in to.

Therefore, when taken advantage, AI can accidentally take a bank password, OTP code or email and make it public on online forums.

Responding to the report, Perplexity spokesperson Jesse Dwyer confirmed that the vulnerability has been identified and patched. However, in the latest experiment, Brave said the error still exists and may continue to be exploited.

Although no real cases of attack have been recorded, Brave warned that the risk is real. The company recommends that Perplexity quickly improve Comet's command processing mechanism, clearly separating user instructions from website content.

At the same time, actions related to sensitive data must have direct confirmation from users.

The incident once again shows that AI browsers, although bringing a new search experience, still have many potential risks.

With AI having deep access to personal data, security and privacy challenges are becoming increasingly urgent.

Cát Tiên (THEO indianexpress)
RELATED NEWS

Notes when using the AI video creation feature with audio of Perplexity Pro

|

Perplexity Pro and Max add an 8-second AI video creation with audio, making it easy for users to download or share in just a few minutes.

Why Perplexity's AI-powered Comet browser could challenge Google

|

Perplexity's new AI browser attracts attention when integrating a smart assistant, challenging Google Chrome's dominance in the web browser market.

Perplexity Pro transforms with 5 worth-trying features for high-end AI users

|

Not only a chatbot, Perplexity Pro provides a smart search engine, image creation, data analysis and programming support.

6 forces participate in the parade and march on the occasion of the 80th Anniversary of National Day

|

There are 6 forces participating in the parade and march at the 80th Anniversary of the August Revolution and National Day on September 2

Concert "Vietnam in Me" will have a donation program for the people of the Central region

|

Despite the impact of storm No. 5, the concert "Vietnam in Me" was still held according to schedule.

Many roads are still unable to circulate, Hanoi opens the floodgates of water regulating reservoirs

|

Due to the impact of storm No. 5, on the afternoon of August 26, many roads in Hanoi were still flooded and could not be used normally.

Storm swept away house, left empty-handed after storm

|

Nghe An - Returning from the evacuation site, Ms. Nguyen Thi Thanh was stunned when her house was swept away by the storm, with only 4 walls left.

Deputy Prime Minister Tran Hong Ha directs maximum mobilization of forces, soon stabilizes people's lives

|

Nghe An - Deputy Prime Minister Tran Hong Ha directed the locality to urgently overcome the consequences of storm No. 5, pay attention to policy beneficiaries, and support people to stabilize their lives.

Notes when using the AI video creation feature with audio of Perplexity Pro

Cá Tiên (THEO indianexpress) |

Perplexity Pro and Max add an 8-second AI video creation with audio, making it easy for users to download or share in just a few minutes.

Why Perplexity's AI-powered Comet browser could challenge Google

Cát Tiên (Theo indianexpress) |

Perplexity's new AI browser attracts attention when integrating a smart assistant, challenging Google Chrome's dominance in the web browser market.

Perplexity Pro transforms with 5 worth-trying features for high-end AI users

Cát Tiên (Theo indianexpress) |

Not only a chatbot, Perplexity Pro provides a smart search engine, image creation, data analysis and programming support.