Comet AI Browser — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
November 11, 2025
Last Seen
March 11, 2026

Comet AI Browser is an AI-enabled web browser platform.

Overview

Comet AI Browser is an AI-enabled web browser platform. Recent disclosures describe a hidden API within the browser that can execute commands on users’ devices, creating potential remote control and takeover capabilities, and they also highlight prompt-injection risks in AI-driven browsers. These findings position Comet AI Browser as a notable cybersecurity concern for both users and developers of AI-assisted web technologies.

Related Threat Clusters

  • Comet AI Browser Vulnerable to Phishing via Agentic Blabbering Exploit

    Perplexity's Comet AI browser has been compromised through a novel attack method called 'Agentic Blabbering', which exploits the browser's interaction with AI services. Analysts from Guardio reported that this phishing…

    2 articles · Updated March 13, 2026
  • Amazon Secures Court Order Against Perplexity's AI Shopping Bots

    A federal judge has granted Amazon a temporary injunction against Perplexity's AI browser, Comet, preventing it from making unauthorized purchases on Amazon. The ruling, issued by Judge Maxine Chesney, indicates that…

    3 articles · Updated March 10, 2026
  • MCP API in Comet Browser Enables Full Device Control via Extensions

    SquareX has revealed a hidden MCP API in the Comet AI browser that allows extensions to execute arbitrary commands on users' devices. This API bypasses security measures found in traditional browsers, posing risks to…

    8 articles · Updated November 19, 2025
  • Security Flaws in AI Browsers Expose Users to Prompt Injection Attacks

    AI browsers, including OpenAI's Atlas and Perplexity’s Comet, are facing significant security vulnerabilities due to prompt injection attacks. These attacks allow malicious actors to manipulate AI systems by injecting…

    11 articles · Updated November 11, 2025
  • HashJack Attack Exploits AI Browsers via URL Manipulation

    Cato Networks has identified a new cybersecurity vulnerability named 'HashJack' that allows attackers to manipulate AI browser assistants by embedding malicious prompts in URL fragments after the '#' symbol. This…

    11 articles · Updated November 27, 2025
  • Comet AI Browser API Allows Unauthorized Device Control

    SquareX researchers have identified a hidden MCP API in the Comet AI browser that enables embedded extensions to execute local commands and potentially take full control of users' devices. This API circumvents…

    6 articles · Updated November 21, 2025

Recent Intelligence Reports

  • Researchers Trick Perplexity's Comet AI Browser Into Phishing Scam in Under Four Minutes — Thehackernews · March 11, 2026
  • Federal judge blocks Perplexity’s AI browser from making Amazon purchases — Cyberscoop · March 10, 2026
  • Comet Browser Flaw Lets Hidden API Run Commands on Users’ Devices — Hackread · November 20, 2025
  • Hidden API in Comet AI browser exposes users to device takeovers — Itbrief.Au · November 19, 2025
  • Hidden API in Comet AI browser exposes users to device takeovers — Securitybrief.Asia · November 19, 2025
  • Hidden API in Comet AI browser exposes users to device takeovers — Securitybrief · November 19, 2025
  • Prompt Injection in AI Browsers — Schneier · November 11, 2025

CVSS v3.1 Breakdown