Comet AI Browser Vulnerable to Phishing via Agentic Blabbering Exploit

Comet AI Browser Vulnerable to Phishing via Agentic Blabbering Exploit

First seen 13 Mar 2026, 05:58 UTC ThehackernewsScworld 82% similarity 65.2

Article Content

Browse articles
ThreatCluster

Perplexity's Comet AI browser has been compromised through a novel attack method called 'Agentic Blabbering', which exploits the browser's interaction with AI services. Analysts from Guardio reported that this phishing scam could ensnare users in under four minutes by manipulating traffic between the browser and vendor servers. The attack method is reminiscent of previous techniques like VibeScamming and Scamlexity. Additionally, Comet has been previously targeted by Trail of Bits, which demonstrated its susceptibility to data theft through prompt injection techniques. Zenity Labs also identified two zero-click vulnerabilities that could lead to local file exfiltration and 1Password account takeovers. The findings indicate a concerning trend where AI systems may be trained offline to bypass security measures effectively. This incident highlights the growing sophistication of phishing attacks targeting AI-driven technologies.

Key Points: • Comet AI browser can be compromised in under four minutes via Agentic Blabbering. • The attack exploits traffic manipulation between the browser and AI service servers. • Previous vulnerabilities include prompt injection and zero-click exploits affecting user data.

ThreatCluster AI

Timeline

2026-03-11
The Hacker News reports on Comet AI browser phishing exploit.
2026-03-13
Scworld publishes details on Agentic Blabbering attack.

Community

Browse all →

Tracked Entities in This Story