Ad
Skip to content

Brave discovers a security flaw in Perplexity’s Comet browser

Brave discovered a security flaw in Perplexity’s AI browser Comet that allows for so-called indirect prompt injection attacks. In these attacks, malicious commands are hidden in web pages or comments and are then interpreted by the AI assistant as legitimate user instructions when summarizing a page. During testing, Brave showed that Comet could be tricked into reading out sensitive user data, like email addresses and one-time passwords, and sending them to attackers. Perplexity responded by issuing updates, but according to Brave, the issue still isn’t fully resolved. Brave also offers its own AI assistant, Leo, in its browser and faces similar security challenges.

AI News Without the Hype – Curated by Humans

Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.

Read on for the full picture.
Subscribe for hype-free coverage.

  • Full access to every article on THE DECODER
  • No ads
  • Join the comments and community discussions
  • A weekly AI news recap via mail
  • 6x/year: "AI Radar" — deep dives on the AI topics that matter most
  • Daily AI news, always up to date
  • Our full ten-year archive
  • Covered by a team with 10+ years in AI
Subscribe to The Decoder