Scworld
Comet AI Browser Vulnerable to Phishing via Agentic Blabbering Exploit
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Perplexity's Comet AI browser has been compromised through a novel attack method called 'Agentic Blabbering', which exploits the browser's interaction with AI services. Analysts from Guardio reported that this phishing scam could ensnare users in under four minutes by manipulating traffic between the browser and vendor servers. The attack method is reminiscent of previous techniques like VibeScamming and Scamlexity. Additionally, Comet has been previously targeted by Trail of Bits, which demonstrated its susceptibility to data theft through prompt injection techniques. Zenity Labs also identified two zero-click vulnerabilities that could lead to local file exfiltration and 1Password account takeovers. The findings indicate a concerning trend where AI systems may be trained offline to bypass security measures effectively. This incident highlights the growing sophistication of phishing attacks targeting AI-driven technologies.
Key Points: • Comet AI browser can be compromised in under four minutes via Agentic Blabbering. • The attack exploits traffic manipulation between the browser and AI service servers. • Previous vulnerabilities include prompt injection and zero-click exploits affecting user data.