A concise reconstruction has not been recorded.
Inspect the ClaimsCase · DiggingBeagle record
Perplexity Comet prompt injection crossed authenticated browser origins
Brave researchers demonstrated that malicious instructions embedded in webpage content could be interpreted as commands when a Comet user summarized a page. Their proof of concept moved across Perplexity and Gmail sessions, recovered an email address and one-time password, and exfiltrated them through the original Reddit context.
Researcher proof of concept against Perplexity Comet. The cited disclosure demonstrates cross-origin access and credential exfiltration in a controlled test; it does not establish widespread or in-the-wild exploitation against Comet users.
30-second account
No separate implication has been established in the canonical account.
Read the stated implicationsThe cited Source demonstrates a researcher-controlled proof of concept and does not establish victim prevalence or realized financial loss. Brave's August 2025 update says the broader attack class was still not fully mitigated, so the disclosure does not support treating the underlying indirect-prompt-injection problem as comprehensively fixed.
Inspect limits and uncertaintyFull canonical reconstruction
Mechanism and trust boundary
Typed chronology
Dates retain their recorded precision. Partially dated events can overlap; display order does not establish a causal sequence.
- Jul 25, 2025Event type unspecified
Brave reports the vulnerability to Perplexity
Brave states that the Comet indirect-prompt-injection vulnerability was discovered and reported to Perplexity.
- Jul 25, 2025notification
Vendor notified
- Jul 27, 2025Event type unspecified
Perplexity acknowledges and deploys an initial fix
Brave reports that Perplexity acknowledged the vulnerability and implemented an initial fix.
- Jul 28, 2025Event type unspecified
Retesting finds the initial fix incomplete
Brave states that retesting showed the initial mitigation was incomplete and additional details were sent to Perplexity.
- Aug 20, 2025Event type unspecified
Brave publicly discloses the Comet prompt-injection PoC
The disclosure demonstrated a Reddit-to-Perplexity-to-Gmail attack path. Brave later updated the post to state that further testing showed this class of attack was still not fully mitigated.
- Aug 20, 2025disclosure
Public disclosure
Claims & evidence
2 independently addressable Claims. Expand a Claim to inspect support, contradiction and scope.
CLM-COMET-IPI-TRIGGERBrave demonstrated an indirect prompt injection embedded in a Reddit comment that was processed when a Comet user invoked the page-summary feature.supported
Basis: reported finding
- supportsAgentic Browser Security: Indirect Prompt Injection in Perplexity Cometprimary disclosure
Attack demonstration, steps describing the malicious Reddit comment and Summarize action
CLM-COMET-IPI-CROSS-ORIGINIn Brave's proof of concept, injected instructions caused Comet to retrieve the victim's Perplexity account email, initiate an OTP flow, read the OTP from an authenticated Gmail session and exfiltrate the email and OTP through a Reddit reply.supported
Basis: reported finding
- supportsAgentic Browser Security: Indirect Prompt Injection in Perplexity Cometprimary disclosure
Attack demonstration, numbered sequence covering Perplexity account access, OTP request, Gmail access and Reddit exfiltration
Implications within the documented scope
Controls and mitigations
No controls or verified fix are recorded.
Unknowns and contradictions
- The cited Source demonstrates a researcher-controlled proof of concept and does not establish victim prevalence or realized financial loss.
- Brave's August 2025 update says the broader attack class was still not fully mitigated, so the disclosure does not support treating the underlying indirect-prompt-injection problem as comprehensively fixed.
Sources and citation
Material revision history
- Sep 25, 2026 · Published version · first publication · revision 50
Cite this record
DiggingBeagle. “Perplexity Comet prompt injection crossed authenticated browser origins.” Published by DiggingBeagle Sep 25, 2026 · Public disclosure Aug 20, 2025. https://diggingbeagle.com/cases/perplexity-comet-prompt-injection-crossed-authenticated-browser-origins/
Citation guidance