Cybersecurity researchers have revealed details of a new attack dubbed CometJacking , which targets Perplexity 's Comet AI browser , embedding malicious instructions inside a seemingly innocent link to extract sensitive data, including from connected services like email and calendar.
See also: Notepad++: DLL Hijacking Vulnerability Allows Code Execution

The prompt injection attack takes the form of a malicious link that, when clicked, triggers unexpected behavior without the victims knowing.
“CometJacking shows how a single, weaponized URL can silently transform an AI browser from a trusted partner to an insider threat,” said Michelle Levy, Head of Security Research at LayerX.
The attack hijacks the browser's built-in AI assistant to steal data, bypassing Perplexity's data protections using simple Base64. The attack does not involve any credential theft element, because the browser already has authorized access to Gmail, Calendar, and other connected services.
It takes place in five steps, triggered when a victim clicks on a specially crafted URL, either sent in a phishing email or found on a web page. Instead of directing the user to the “intended” destination, the URL instructs the Comet browser AI to execute a hidden prompt that captures the user’s data from Gmail, obfuscates it using Base64 encoding, and transmits the information to a checkpoint under the attacker’s control.
See also: BitlockMove tool allows lateral movement & COM Hijacking

The crafted URL is a query string directed to the AI Comet browser, with the malicious directive added using the “collection” parameter of the URL, causing the agent to consult its memory instead of performing a live web search.
While Perplexity has characterized the findings as “no security impact,” they highlight how AI-native tools introduce new security risks that can bypass traditional defenses, allowing malicious actors to exploit them and expose users and organizations to potential data theft.
In August 2020, Guardio Labs revealed an attack technique called Scamlexity, where browsers like Comet could be tricked by malicious actors into interacting with phishing pages or fake online stores without the knowledge or intervention of the human user.
See also: MassJacker: New malicious campaign steals crypto users

“AI browsers are the next battleground for enterprises,” said Or Eshed, CEO of LayerX. “When an attacker can direct your assistant with a link, the browser becomes a command and control point within the company’s perimeter. Organizations urgently need to evaluate controls that detect and neutralize malicious agent prompts before they become widespread campaigns.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
