Vulnerability in Perplexity’s Comet Browser Screenshot Feature Allows Malicious Prompt Injection
On October 21, 2025, a critical security vulnerability was disclosed in Perplexity's Comet AI browser. This vulnerability allows attackers to inject malicious commands through hidden text in screenshots, posing a significant risk to user accounts,…
On October 21, 2025, a critical security vulnerability was disclosed in Perplexity's Comet AI browser. This vulnerability allows attackers to inject malicious commands through hidden text in screenshots, posing a significant risk to user accounts, including banking and email services.
How Attackers Hide Dangerous Instructions in Images
The vulnerability leverages a technique known as steganography, which embeds nearly invisible instructions within web content. Researchers at Brave demonstrated a proof-of-concept attack using faint light blue text on a yellow background, rendering the malicious commands nearly invisible to users.
When users take a screenshot of such a webpage, Comet's browser utilizes optical character recognition (OCR) to extract all text, including the hidden malicious commands. These commands are then sent to the AI system without filtering or validation.
This vulnerability allows attackers to manipulate the browser into executing unauthorized actions by treating hidden instructions as legitimate commands. The potential impact is significant for users who keep important accounts logged in during browsing sessions.
If a prompt is successfully injected into Comet, the AI could gain access to sensitive user accounts, such as bank accounts and emails, compromise corporate systems, or exfiltrate data from cloud storage.
On October 21, 2025, a critical security vulnerability was disclosed in Perplexity's Comet AI browser.
The vulnerability bypasses traditional web security measures like the same-origin policy, which typically prevents websites from accessing each other's data.
Researchers Artem Chaikin and Shivan Kaul Sahib from Brave also identified similar vulnerabilities in other agentic browsers, such as Fellou, where visible webpage content could be used to inject commands by merely navigating to a malicious site.
The vulnerability was responsibly reported to Perplexity on October 1, 2025, providing the company with an opportunity to address the issue before the public disclosure.
This research highlights a fundamental design flaw in how AI browsers manage the boundary between user commands and untrusted web content. Until AI browsers implement appropriate safety measures to separate content and commands, they should be considered inherently risky.
Security experts recommend isolating AI browsing features from regular browsing and only activating them upon explicit user request. Users should avoid keeping sensitive accounts logged in while using such features or refrain from using these tools until stronger protections are established.
Based on reporting by GBHackers.
