BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CometJacking Attack Exploits AI Browser to Steal Sensitive Data

  • A new attack named CometJacking targets Perplexity‘s agentic AI browser Comet via malicious embedded prompts.
  • The attack uses a deceptive link to extract sensitive data from connected services like email and calendar.
  • CometJacking bypasses existing data protection by using simple Base64-encoding for data exfiltration.
  • The attack requires no credential theft since the browser already has authorized access to user accounts.
  • Experts warn AI-enabled browsers pose new security threats that need built-in protections for prompt and memory handling.

Cybersecurity experts have revealed details of a newly identified attack called CometJacking, which exploits Perplexity‘s AI-powered browser, Comet. This method uses malicious prompts hidden inside seemingly harmless links to steal sensitive data from services linked to the browser, such as email and calendar.

- Advertisement -

The attack unfolds when a user clicks a specially crafted URL that triggers the browser’s AI to execute a hidden command. This command gathers private information from connected accounts, encodes the data with Base64 (a simple text encoding method), and sends it to a server controlled by the attacker. The entire process bypasses standard protections as it does not involve stealing user credentials, relying instead on the browser’s existing authorized access.

Michelle Levy, Head of Security Research at LayerX, said, “CometJacking shows how a single, weaponized URL can quietly flip an AI browser from a trusted co-pilot to an insider threat.” She added, “Our research proves that trivial obfuscation can bypass data exfiltration checks and pull email, calendar, and connector data off-box in one click.” Levy emphasized the need for AI browsers to incorporate security throughout their design, especially around agent prompts and memory access, not just web page content.

The malicious link uses their “collection” parameter to instruct the AI agent to access stored prompts, avoiding real-time web searches. While Perplexity has stated their findings pose “no security impact,” the incident raises concerns about new vulnerabilities inherent in AI-native tools. These risks challenge traditional defenses and highlight how attackers could misuse AI assistants within browsers.

This follows a 2020 attack called Scamlexity, disclosed by Guardio Labs, which showed how browsers like Comet could be manipulated into interacting with phishing or fake shopping sites without user knowledge. Or Eshed, CEO of LayerX, noted, “AI browsers are the next enterprise battleground,” and urged organizations to actively develop systems to detect and block malicious AI prompts before such attacks become common.

- Advertisement -

For more information on the attack, see the full report at LayerX’s blog.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

OpenFX Raises $94M Series A for Stablecoin Payments Growth

Fintech startup OpenFX raised $94 million in a Series A round to scale its...

Dromos Launches Predictive Allocation for Real-Time Voting

Dromos Labs unveiled "Predictive Allocation," a new feature at EthCC in Cannes.The feature allows...

Senators Probe SEC Over Favoritism in Trump-Linked Crypto Cases

Two Democratic senators, Richard Blumenthal and Elizabeth Warren, are demanding answers from SEC Chair...

Sen. Blumenthal Probes SEC for Crypto Favoritism to Trump Allies

Connecticut Senator Richard Blumenthal has formally requested records from the Securities and Exchange Commission...

SpaceX may bar Robinhood, SoFi from IPO share sales – Reuters

SpaceX is reportedly considering excluding platforms like Robinhood (HOOD) and SoFi from its upcoming...

Must Read

Crypto in New York: The 2026 Guide to Legal Exchanges and BitLicense Regulations

TL;DR: Trading crypto in New York is legal but heavily regulated by the New York Department of Financial Services (NYDFS). Platforms must hold a BitLicense...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading