Perplexity’s Comet AI browser may have some worrying security flaws that could allow a hacker to hijack your device



  • SquareX discovered a hidden MCP API in the Comet browser that allowed arbitrary local commands to be executed
  • A vulnerability in the Agentic extension could allow attackers to hijack devices via the compromised perplexity.ai site
  • The demo showed the execution of WannaCry; Researchers warn that catastrophic third-party risk is inevitable.

Cybersecurity experts at SquareX claim to have found a major vulnerability in Comet, the AI ​​browser created by Perplexity, that could allow threat actors to completely take over a victim’s device.

SquareX discovered that the browser has a hidden API capable of executing local commands (commands on the underlying operating system, rather than just the browser).



Leave a Comment

Your email address will not be published. Required fields are marked *