Analytics Extension - Tool

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 19, 2025
Last Seen
November 19, 2025

Analytics Extension appears to be a cybersecurity tool/attack vector tied to a hidden API inside the Comet AI browser.

Overview

Analytics Extension appears to be a cybersecurity tool/attack vector tied to a hidden API inside the Comet AI browser. Its hallmark is a covert API exposure that can be abused within the browser context to take control of user devices. This underscores the growing risk of browser-based attack surfaces and the importance of secure analytics tooling in enterprise environments.

Related Threat Clusters

  • MCP API in Comet Browser Enables Full Device Control via Extensions

    SquareX has revealed a hidden MCP API in the Comet AI browser that allows extensions to execute arbitrary commands on users' devices. This API bypasses security measures found in traditional browsers, posing risks to…

    8 articles · Updated November 19, 2025
  • Comet AI Browser API Allows Unauthorized Device Control

    SquareX researchers have identified a hidden MCP API in the Comet AI browser that enables embedded extensions to execute local commands and potentially take full control of users' devices. This API circumvents…

    6 articles · Updated November 21, 2025

Recent Intelligence Reports

  • Hidden API in Comet AI browser exposes users to device takeovers — Itbrief.Au · November 19, 2025
  • Hidden API in Comet AI browser exposes users to device takeovers — Securitybrief.Asia · November 19, 2025

CVSS v3.1 Breakdown