Skip to content
MCP API in Comet Browser Enables Full Device Control via Extensions

MCP API in Comet Browser Enables Full Device Control via Extensions

First seen 19 Nov 2025, 16:15 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

SquareX has revealed a hidden MCP API in the Comet AI browser that allows extensions to execute arbitrary commands on users' devices. This API bypasses security measures found in traditional browsers, posing risks to user data and device integrity. The discovery raises significant security concerns for users of AI-powered browsers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 196d ago How this analysis works

More articles in this cluster (8)

Following this threat?

Track WannaCry, Comet and Perplexity in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed