Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

How Tesla’s (TSLA) Robotaxi, AI Deals and U.K. Energy Push Could Shape Software Revenue Growth

InMind: Evaluating LLMs in Capturing and Applying Individual Human Reasoning Styles – Takara TLDR

Why AI Stocks Are Giving Some Investors Dotcom Bubble Déjà Vu

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Business AI
    • Advanced AI News Features
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
Perplexity AI

Perplexity Comet’s flaw exposes how dangerous agentic AI can be

By Advanced AI EditorAugust 25, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Perplexity Comet's flaw exposes how dangerous agentic AI can be

The flaw could lead to account hijacking

What’s the story

A new research has revealed a major security flaw in Perplexity’s Comet, an AI-driven “agentic” web browser.
The vulnerability, discovered by Brave’s senior mobile security engineer Artem Chaikin and VP of Privacy and Security Shivan Kaul Sahib, exposes users to potential account hijacking.
The issue stems from how Comet handles webpage content when asked to summarize it.

How the attack works

The flaw in Comet lies in its inability to differentiate between user commands and untrusted content from webpages.
When asked to summarize a page, it directly feeds part of the webpage to its large language model (LLM).
This creates an opportunity for attackers to inject indirect prompt injection payloads that the AI will execute as commands.
For instance, a hacker could use this method to access a user’s emails by hiding malicious instructions behind a spoiler tag on Reddit.

Once the user visits the webpage, the attack is triggered

When an unsuspecting user visits this compromised webpage and uses the browser’s AI assistant feature, the attack is triggered.
The AI processes the webpage content and sees hidden malicious instructions, treating everything as user requests.
The injected commands then instruct the AI to misuse its browser tools, like visiting a user’s banking site and stealing saved passwords or exfiltrating sensitive information to an attacker-controlled server.

The attack poses a challenge to web security measures

The attack poses a major challenge to existing web security measures.
When an AI assistant follows malicious instructions from untrusted webpage content, traditional protections like same-origin policy (SOP) or cross-origin resource sharing (CORS) become ineffective.
The AI operates with the user’s full privileges across authenticated sessions, potentially giving access to banking accounts, corporate systems, private emails, cloud storage and other services.

Key characteristics of this new AI attack

Unlike traditional web vulnerabilities that affect individual sites or require complex exploitation, this attack enables cross-domain access through simple, natural language instructions embedded in websites.
The malicious instructions could even be included in user-generated content on a website the attacker doesn’t control (for example, attack instructions hidden in a Reddit comment).
The attack is both indirect in interaction and browser-wide in scope.

How to prevent such attacks?

To prevent such attacks, the browser should clearly separate user instructions from website contents when sending them as context to the model.
The contents of the page should always be treated as untrusted.
Also, based on task and context, the model comes up with actions for the browser to take; these actions should be checked for alignment against user’s requests.



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleBeyond Pass@1: Self-Play with Variational Problem Synthesis Sustains RLVR – Takara TLDR
Next Article Tesla Partners with DeepSeek and ByteDance to Launch AI Voice Assistant in China
Advanced AI Editor
  • Website

Related Posts

Perplexity AI Compares XRP to Top Altcoins

August 19, 2025

After Perplexity AI, Airtel Brings Free Apple Music To Prepaid Users: How To Get It Now

August 19, 2025

Perplexity AI Makes $34.5 Billion Cash Bid For Google Chrome, Backed By Funds As Analyst Says Offer ‘Vastly Undervalues’ Asset – Apollo Asset Management (NYSE:APO), Alphabet (NASDAQ:GOOG)

August 18, 2025

Comments are closed.

Latest Posts

Mütter Museum in Philadelphia Announces New Policy for Human Remains

Inigo Philbrick, Art Dealer Convicted of Fraud, Appears in BBC Film

Links for August 22, 2025

White House Targets Specific Artworks at Smithsonian Museums

Latest Posts

How Tesla’s (TSLA) Robotaxi, AI Deals and U.K. Energy Push Could Shape Software Revenue Growth

August 25, 2025

InMind: Evaluating LLMs in Capturing and Applying Individual Human Reasoning Styles – Takara TLDR

August 25, 2025

Why AI Stocks Are Giving Some Investors Dotcom Bubble Déjà Vu

August 25, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • How Tesla’s (TSLA) Robotaxi, AI Deals and U.K. Energy Push Could Shape Software Revenue Growth
  • InMind: Evaluating LLMs in Capturing and Applying Individual Human Reasoning Styles – Takara TLDR
  • Why AI Stocks Are Giving Some Investors Dotcom Bubble Déjà Vu
  • IBM and NASA Develop a Digital Twin of the Sun to Predict Future Solar Storms
  • Tesla Partners with DeepSeek and ByteDance to Launch AI Voice Assistant in China

Recent Comments

  1. JamesFug on Marc Raibert: Boston Dynamics and the Future of Robotics | Lex Fridman Podcast #412
  2. MarvinDit on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  3. JeffreyNipsy on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  4. slot online 4d on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  5. Психолог on 12 AI Copywriting Tools for Faster, Smarter Content Creation (2025)

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.