On August 26, security company Brave Software disclosed that a browser called Comet from Perplexity AI had a serious security vulnerability. Attackers could embed hidden instructions in web pages to trick the AI assistant into leaking users' private data, including emails and codes.
Brave researchers demonstrated that when users asked Comet to summarize Reddit pages containing hidden commands, the AI assistant executed those commands. Although Perplexity claimed that the issue was fixed before it was discovered and that no user data was leaked, Brave insisted that the vulnerability was still exploitable weeks after the fix and warned that Comet's design architecture made it vulnerable to further attacks. (Decrypt)