HomeSecurityHow Perplexity's Comet AI Browser can be involved in phishing...

How Perplexity's Comet AI Browser can be involved in a phishing scam

Agentic web browsers that leverage artificial intelligence (e.g., Perplexity's Comet AI) to autonomously perform actions on multiple websites, on behalf of a user, can be trained and tricked into falling victim to phishing and scams.

Comet AI

According to a report by Guardio, the attack exploits the tendency of AI browsers to justify their actions and uses this tendency against the model itself to reduce security safeguards its.

See also: Judge blocks Perplexity's AI agents from Amazon shopping

“AI now operates in real time, within messy and dynamic pages, while constantly requesting information, making decisions, and narrating its actions. Well, ‘narrating’ is probably an understatement – ​​It says a lot!” said security researcher Shaked Chen.

“We call this Agentic Blabbering: the AI ​​Browser exposes what it sees, what it thinks is happening, what it plans to do next, and which signals it considers suspicious or safe.”“.

Comet AI Browser Scam

By intercepting traffic between the browser and AI servicesrunning on the vendor's servers and feeding it into a Generative Adversarial Network (GAN), Guardio managed to make Perplexity's Comet AI browser fall victim to a phishing scam in less than four minutes.

See also: Comet: Perplexity launches AI browser on Android

How Perplexity's Comet AI Browser can be involved in a phishing scam

The research builds on previous techniques such as VibeScamming and Scamlexity, which found that vibe-coding platforms and AI browsers can be tricked into creating scam pages or performing malicious actions through hidden prompt injections. With the AI ​​agent handling the tasks without constant human supervision, there is a shift in the attack surface where a scam no longer needs to trick a user. Instead, it aims to trick the AI ​​model itself.

“If you can observe what the agent flags as suspicious, what it hesitates about, and what it thinks and narrates about the page, you can do that. You can use those as training signals,” Chen explained. “The deception progresses until the AI ​​Browser reliably walks into the trap that another AI has set for it.”

The idea is to create a “scam engine” that optimizes and regenerates a phishing page until the agentic browser stops complaining and proceeds to execute the malicious actor’s commands, such as entering a victim’s credentials into a fake website designed to execute a refund scam.

See also: Perplexity's Comet AI browser comes to iPhone

How Perplexity's Comet AI Browser can be involved in a phishing scam

What makes this attack interesting and dangerous is that once the attacker repurposes a website to work against a specific AI browser, it works on all users who rely on the same agent. The target has shifted from the human user to the AI ​​browser.

“This reveals the unfortunate near future we face: scams will not only be launched and adapted in the field, they will be trained offline, against the model that millions of users rely on,” Guardio said. “Because when your browser AI explains why it stopped, it teaches attackers how to bypass it.”

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS