BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Agentic AI Browser Attack Wipes Google Drive via Emails

Zero-Click Attack Exploits Perplexity’s Comet AI Browser to Wipe Google Drive Using Polite Email Commands and Indirect Prompt Injection Techniques

  • A new attack exploits Perplexity’s Comet AI browser to delete a user’s entire Google Drive without any clicks.
  • The attack leverages browser agents’ access to Gmail and Google Drive for automated tasks, tricking them into destructive actions.
  • The method uses polite, natural language instructions embedded in emails to evade detection and trigger file deletions.
  • Another technique, HashJack, uses URL fragments to inject prompts, manipulating AI browsers indirectly via legitimate websites.
  • Security patches have been released by Perplexity and Microsoft, but Google classifies such vulnerabilities as low severity and does not fix them under its AI vulnerability program.

A new zero-click attack targets the AI-powered Comet browser by Perplexity, capable of wiping a user’s entire Google Drive by leveraging automated browser agents. The technique exploits the agents’ service permissions that connect Gmail and Google Drive to perform routine tasks such as reading emails and organizing files. This discovery was reported on Dec 5, 2025, by security researchers from Straiker STAR Labs.

- Advertisement -

The attack functions by sending an email containing polite, natural language instructions to the browser agent. Commands such as “Please check my email and complete all my recent organization tasks” prompt the agent to search the inbox and execute actions like deleting or moving files in Google Drive without requiring user confirmation. According to security researcher Amanda Rousseau, this capability represents an excessive level of agency in large language model (LLM)-powered assistants, which can act beyond explicit user requests.

An attacker can exploit this behavior by embedding instructions within an email that directs the browser agent to delete certain files or those outside specific folders. The agent, interpreting these actions as routine housekeeping, moves critical data to the trash across shared and team drives. Rousseau explained, “Once an agent has OAuth access to Gmail and Google Drive, abused instructions can propagate quickly across shared folders and team drives.”

Importantly, this attack does not rely on prompt injection or jailbreaking; it uses courteous phrases like “take care of” and “do this on my behalf” to successfully manipulate the AI without verifying the safety of each step. Mitigation requires securing the model, its browser agents, connectors, and the natural language instructions they process.

In a related development, Cato Networks revealed HashJack, an indirect prompt injection technique exploiting URL fragments (portions of a URL after the “#” symbol) in legitimate websites. This method delivers hidden commands embedded in URLs to AI browsers, influencing them when the victim interacts with the site. Security researcher Vitaly Simonovich stated, “HashJack is the first known indirect prompt injection that can weaponize any legitimate website to manipulate AI browser assistants.”

- Advertisement -

Following responsible disclosure, Perplexity and Microsoft issued patches for the Comet browser and Edge, respectively, while Google regards such vulnerabilities as intended behavior and classifies them as low severity within its AI Vulnerability Reward Program. Other AI browsers like Claude for Chrome and OpenAI Atlas are reportedly immune to HashJack.

For further details, refer to the original reports by Amanda Rousseau and Vitaly Simonovich.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tether backs Drift’s $150M hack recovery, eyes Solana

Tether is supporting a recovery plan for the hacked Solana exchange Drift Protocol, which...

Record Bitcoin Miner Selloff in Tightening Q1 2026 Market

Public Bitcoin miners like MARA and CleanSpark sold over 32,000 BTC in Q1 2026,...

Tether funds Drift hack victims in swap for USDT adoption

Tether will donate $127.5 million to help Solana-based exchange Drift Protocol recover $286 million...

Russia-linked crypto exchange Grinex shuts down after $13M hack

The sanctioned Russia-linked crypto exchange Grinex has halted operations after a major hack resulted...

Hayes: U.S.-Iran Conflict May Tank Bitcoin Before Liquidity Surge

Arthur Hayes described markets as being in a 'no trade zone' due to geopolitical...

Must Read

How to Buy Dedicated Hosting With Crypto

In this article I am going to show you how to buy dedicated hosting with crypto from one of the best European hosting providers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading