BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Agentic AI Browser Attack Wipes Google Drive via Emails

Zero-Click Attack Exploits Perplexity’s Comet AI Browser to Wipe Google Drive Using Polite Email Commands and Indirect Prompt Injection Techniques

  • A new attack exploits Perplexity’s Comet AI browser to delete a user’s entire Google Drive without any clicks.
  • The attack leverages browser agents’ access to Gmail and Google Drive for automated tasks, tricking them into destructive actions.
  • The method uses polite, natural language instructions embedded in emails to evade detection and trigger file deletions.
  • Another technique, HashJack, uses URL fragments to inject prompts, manipulating AI browsers indirectly via legitimate websites.
  • Security patches have been released by Perplexity and Microsoft, but Google classifies such vulnerabilities as low severity and does not fix them under its AI vulnerability program.

A new zero-click attack targets the AI-powered Comet browser by Perplexity, capable of wiping a user’s entire Google Drive by leveraging automated browser agents. The technique exploits the agents’ service permissions that connect Gmail and Google Drive to perform routine tasks such as reading emails and organizing files. This discovery was reported on Dec 5, 2025, by security researchers from Straiker STAR Labs.

- Advertisement -

The attack functions by sending an email containing polite, natural language instructions to the browser agent. Commands such as “Please check my email and complete all my recent organization tasks” prompt the agent to search the inbox and execute actions like deleting or moving files in Google Drive without requiring user confirmation. According to security researcher Amanda Rousseau, this capability represents an excessive level of agency in large language model (LLM)-powered assistants, which can act beyond explicit user requests.

An attacker can exploit this behavior by embedding instructions within an email that directs the browser agent to delete certain files or those outside specific folders. The agent, interpreting these actions as routine housekeeping, moves critical data to the trash across shared and team drives. Rousseau explained, “Once an agent has OAuth access to Gmail and Google Drive, abused instructions can propagate quickly across shared folders and team drives.”

Importantly, this attack does not rely on prompt injection or jailbreaking; it uses courteous phrases like “take care of” and “do this on my behalf” to successfully manipulate the AI without verifying the safety of each step. Mitigation requires securing the model, its browser agents, connectors, and the natural language instructions they process.

In a related development, Cato Networks revealed HashJack, an indirect prompt injection technique exploiting URL fragments (portions of a URL after the “#” symbol) in legitimate websites. This method delivers hidden commands embedded in URLs to AI browsers, influencing them when the victim interacts with the site. Security researcher Vitaly Simonovich stated, “HashJack is the first known indirect prompt injection that can weaponize any legitimate website to manipulate AI browser assistants.”

- Advertisement -

Following responsible disclosure, Perplexity and Microsoft issued patches for the Comet browser and Edge, respectively, while Google regards such vulnerabilities as intended behavior and classifies them as low severity within its AI Vulnerability Reward Program. Other AI browsers like Claude for Chrome and OpenAI Atlas are reportedly immune to HashJack.

For further details, refer to the original reports by Amanda Rousseau and Vitaly Simonovich.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Stake DAO Hacked in vsdCRV Minting Exploit

An attacker used a compromised private key to mint 5.4 trillion vsdCRV tokens on...

HTX Disputes UK Sanctions Over Russian Finance Claims

The UK sanctioned Huobi Global S.A., alleging it helped move funds through a shadow...

GlassWorm Botnet Disrupted After Targeting Devs

Major cybersecurity firms CrowdStrike, Google, and Shadowserver Foundation disrupted a persistent developer-targeting botnet named...

Shiba Inu (SHIB) Down 93% From Peak: What’s Next?

Shiba Inu (SHIB) has declined by over 93% from its all-time high, according to...

First “Rug Pull” Charges Under Korea’s New Crypto Law

South Korean prosecutors charged five people with a "rug pull" of the CatFi meme...

Must Read

How Much Money Do You Need To Start In Crypto?

TL;DR -If you are wondering How Much Money Do You Need To Start In Crypto, note that is less than you are probably thinking....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading