Itbrief.Au
Comet AI Browser API Allows Unauthorized Device Control
First seen 2 Dec 2025, 18:33 UTC
•



+1
•87% similarity
•10.7
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
SquareX researchers have identified a hidden MCP API in the Comet AI browser that enables embedded extensions to execute local commands and potentially take full control of users' devices. This API circumvents traditional browser security measures, allowing unauthorized access to device resources without user consent.
ThreatCluster AI
How this analysis works