Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

C3.AI DEADLINE FOR LEADERSHIP is October 21, 2025 in a Securities Fraud Lawsuit – Contact Kaplan Fox & Kilsheimer LLP

A^2Search: Ambiguity-Aware Question Answering with Reinforcement Learning – Takara TLDR

MIT president rejects proposal tying funding to Trump’s political agenda

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Business AI
    • Advanced AI News Features
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
Perplexity AI

Perplexity Comet’s flaw exposes how dangerous agentic AI can be

By Advanced AI EditorAugust 25, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Perplexity Comet's flaw exposes how dangerous agentic AI can be

The flaw could lead to account hijacking

What’s the story

A new research has revealed a major security flaw in Perplexity’s Comet, an AI-driven “agentic” web browser.
The vulnerability, discovered by Brave’s senior mobile security engineer Artem Chaikin and VP of Privacy and Security Shivan Kaul Sahib, exposes users to potential account hijacking.
The issue stems from how Comet handles webpage content when asked to summarize it.

How the attack works

The flaw in Comet lies in its inability to differentiate between user commands and untrusted content from webpages.
When asked to summarize a page, it directly feeds part of the webpage to its large language model (LLM).
This creates an opportunity for attackers to inject indirect prompt injection payloads that the AI will execute as commands.
For instance, a hacker could use this method to access a user’s emails by hiding malicious instructions behind a spoiler tag on Reddit.

Once the user visits the webpage, the attack is triggered

When an unsuspecting user visits this compromised webpage and uses the browser’s AI assistant feature, the attack is triggered.
The AI processes the webpage content and sees hidden malicious instructions, treating everything as user requests.
The injected commands then instruct the AI to misuse its browser tools, like visiting a user’s banking site and stealing saved passwords or exfiltrating sensitive information to an attacker-controlled server.

The attack poses a challenge to web security measures

The attack poses a major challenge to existing web security measures.
When an AI assistant follows malicious instructions from untrusted webpage content, traditional protections like same-origin policy (SOP) or cross-origin resource sharing (CORS) become ineffective.
The AI operates with the user’s full privileges across authenticated sessions, potentially giving access to banking accounts, corporate systems, private emails, cloud storage and other services.

Key characteristics of this new AI attack

Unlike traditional web vulnerabilities that affect individual sites or require complex exploitation, this attack enables cross-domain access through simple, natural language instructions embedded in websites.
The malicious instructions could even be included in user-generated content on a website the attacker doesn’t control (for example, attack instructions hidden in a Reddit comment).
The attack is both indirect in interaction and browser-wide in scope.

How to prevent such attacks?

To prevent such attacks, the browser should clearly separate user instructions from website contents when sending them as context to the model.
The contents of the page should always be treated as untrusted.
Also, based on task and context, the model comes up with actions for the browser to take; these actions should be checked for alignment against user’s requests.



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleBurlington’s ‘reimagined’ store layout aims to make shopping easier
Next Article Tesla Partners with DeepSeek and ByteDance to Launch AI Voice Assistant in China
Advanced AI Editor
  • Website

Related Posts

Detroit Free Press partners with Perplexity: Why it matters

October 11, 2025

How to get Perplexity Pro free for a year – you have 3 options

October 10, 2025

Indian Techie Uses Perplexity’s Comet Browser To Complete Coursera AI Course In Seconds; CEO Aravind Srinivas Responds

October 10, 2025

Comments are closed.

Latest Posts

The Rubin Names 2025 Art Prize, Research and Art Projects Grants

Kochi-Muziris Biennial Announces 66 Artists for December Exhibition

Instagram Launches ‘Rings’ Awards for Creators—With KAWS as a Judge

Museums Prepare to Close Their Doors as Government Shutdown Continues

Latest Posts

C3.AI DEADLINE FOR LEADERSHIP is October 21, 2025 in a Securities Fraud Lawsuit – Contact Kaplan Fox & Kilsheimer LLP

October 12, 2025

A^2Search: Ambiguity-Aware Question Answering with Reinforcement Learning – Takara TLDR

October 12, 2025

MIT president rejects proposal tying funding to Trump’s political agenda

October 12, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • C3.AI DEADLINE FOR LEADERSHIP is October 21, 2025 in a Securities Fraud Lawsuit – Contact Kaplan Fox & Kilsheimer LLP
  • A^2Search: Ambiguity-Aware Question Answering with Reinforcement Learning – Takara TLDR
  • MIT president rejects proposal tying funding to Trump’s political agenda
  • Learning on the Job: An Experience-Driven Self-Evolving Agent for Long-Horizon Tasks – Takara TLDR
  • Assessing Valuation After NVIDIA AI Partnership and Manufacturing Expansion

Recent Comments

  1. JungleEchoK2Nalay on Google DeepMind’s Demis Hassabis Wants to Build AI Email Assistant That Can Reply in Your Style: Report
  2. JungleEchoK2Nalay on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  3. parifoot-611 on Marc Raibert: Boston Dynamics and the Future of Robotics | Lex Fridman Podcast #412
  4. beste app für wetten on C3.ai Stock Dips Following Palantir Technologies Earnings: What’s Going On? – C3.ai (NYSE:AI)
  5. https://plus.Chidaneh.com/ht-ft-wetten-2 on A Library of LLM Intrinsics for Retrieval-Augmented Generation

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.