Source · DiggingBeagle record
Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet
Brave security researchers' proof-of-concept disclosure showing indirect prompt injection in Perplexity Comet crossing authenticated browser origins and exfiltrating account data.
- Published
- Aug 20, 2025
- Source role
- primary disclosure
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Brave security researchers' proof-of-concept disclosure showing indirect prompt injection in Perplexity Comet crossing authenticated browser origins and exfiltrating account data.
Claim-level citations (2)
- supportsPerplexity Comet prompt injection crossed authenticated browser origins: Brave demonstrated an indirect prompt injection embedded in a Reddit comment that was processed when a Comet user invoked the page-summary feature.
Attack demonstration, steps describing the malicious Reddit comment and Summarize action
- supportsPerplexity Comet prompt injection crossed authenticated browser origins: In Brave's proof of concept, injected instructions caused Comet to retrieve the victim's Perplexity account email, initiate an OTP flow, read the OTP from an authenticated Gmail session and exfiltrate the email and OTP through a Reddit reply.
Attack demonstration, numbered sequence covering Perplexity account access, OTP request, Gmail access and Reddit exfiltration
Cite this record
DiggingBeagle. “Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet.” Published Aug 20, 2025. https://diggingbeagle.com/sources/agentic-browser-security-indirect-prompt-injection-in-perplexity-comet/
Citation guidance