‘The attack requires no exploitation, no user clicks or explicit request for sensitive actions’: Experts say Perplexity’s AI Comet browser can be hijacked to steal your passwords



  • Zenity researchers discovered please fixa no-click indirect injection bug in Comet browser
  • Malicious calendar invites could trick AI into extracting passwords and sensitive files without the user realizing
  • Fixed bug with restrictions on access to file://, preventing agents from reading the local file system

Perplexity’s AI-powered Comet web browser is vulnerable to rapid injection indirect attacks, which threat actors can exploit to leak sensitive data such as passwords, experts warned.

Security researchers Zenity named the flaw PleaseFix and demonstrated different ways it can be abused.



Leave a Comment

Your email address will not be published. Required fields are marked *