Case · DiggingBeagle record

Perplexity Comet prompt injection crossed authenticated browser origins

Brave researchers demonstrated that malicious instructions embedded in webpage content could be interpreted as commands when a Comet user summarized a page. Their proof of concept moved across Perplexity and Gmail sessions, recovered an email address and one-time password, and exfiltrated them through the original Reddit context.

Evidence boundary

Researcher proof of concept against Perplexity Comet. The cited disclosure demonstrates cross-origin access and credential exfiltration in a controlled test; it does not establish widespread or in-the-wild exploitation against Comet users.

Not yet assessed. The record's Claims and Sources remain available; missing grades do not mean low impact.Assessment method

30-second account

Mechanism and trust boundary

Typed chronology

Dates retain their recorded precision. Partially dated events can overlap; display order does not establish a causal sequence.

  1. Jul 25, 2025
    Event type unspecified

    Brave reports the vulnerability to Perplexity

    Brave states that the Comet indirect-prompt-injection vulnerability was discovered and reported to Perplexity.

  2. Jul 25, 2025
    notification

    Vendor notified

  3. Jul 27, 2025
    Event type unspecified

    Perplexity acknowledges and deploys an initial fix

    Brave reports that Perplexity acknowledged the vulnerability and implemented an initial fix.

  4. Jul 28, 2025
    Event type unspecified

    Retesting finds the initial fix incomplete

    Brave states that retesting showed the initial mitigation was incomplete and additional details were sent to Perplexity.

  5. Aug 20, 2025
    Event type unspecified

    Brave publicly discloses the Comet prompt-injection PoC

    The disclosure demonstrated a Reddit-to-Perplexity-to-Gmail attack path. Brave later updated the post to state that further testing showed this class of attack was still not fully mitigated.

  6. Aug 20, 2025
    disclosure

    Public disclosure

Claims & evidence

2 independently addressable Claims. Expand a Claim to inspect support, contradiction and scope.

CLM-COMET-IPI-TRIGGERBrave demonstrated an indirect prompt injection embedded in a Reddit comment that was processed when a Comet user invoked the page-summary feature.supported

Basis: reported finding

Permanent Claim anchor
CLM-COMET-IPI-CROSS-ORIGINIn Brave's proof of concept, injected instructions caused Comet to retrieve the victim's Perplexity account email, initiate an OTP flow, read the OTP from an authenticated Gmail session and exfiltrate the email and OTP through a Reddit reply.supported

Basis: reported finding

Permanent Claim anchor

Implications within the documented scope

Controls and mitigations

No controls or verified fix are recorded.

Unknowns and contradictions

  • The cited Source demonstrates a researcher-controlled proof of concept and does not establish victim prevalence or realized financial loss.
  • Brave's August 2025 update says the broader attack class was still not fully mitigated, so the disclosure does not support treating the underlying indirect-prompt-injection problem as comprehensively fixed.

Sources and citation

Material revision history

  1. Sep 25, 2026 · Published version · first publication · revision 50

Cite this record

DiggingBeagle. “Perplexity Comet prompt injection crossed authenticated browser origins.” Published by DiggingBeagle Sep 25, 2026 · Public disclosure Aug 20, 2025. https://diggingbeagle.com/cases/perplexity-comet-prompt-injection-crossed-authenticated-browser-origins/

Citation guidance

Independent research

The source stays with the story.

Claims, evidence and corrections remain inspectable. About the project · Our methodology