Comet AI Browser API Allows Unauthorized Device Control

Comet AI Browser API Allows Unauthorized Device Control

First seen 2 Dec 2025, 18:33 UTC CsoonlineSecuritybriefSecuritybrief.AsiaItbrief.AuHackread+1 87% similarity 10.7

Article Content

Browse articles
ThreatCluster

SquareX researchers have identified a hidden MCP API in the Comet AI browser that enables embedded extensions to execute local commands and potentially take full control of users' devices. This API circumvents traditional browser security measures, allowing unauthorized access to device resources without user consent.

ThreatCluster AI How this analysis works

Community

Browse all →