New Delhi: There are many companies that are progressively rolling out their agentic browsers, web browsers that can perform tasks on the user’s behalf. There are some security issues that should not be overlooked. There is an news came to know, that Perplexity’s Comet AI browsers can be hijacked with some misleading instructions, means they can release their user’s some of the personal details, which is not an good sign for them in the terms of building this, means if this can happened them those hackers can easily access to the user’s personal details which is not a good thing.
Brave’s security teams have disclosed a critical prompt injection in Perplexity’s Comet AI browser; this indirect prompt injection can easily misguide the AI Agent into revealing sensitive information. When this AI agent asked to summarise a webpage, it did not clearly separate the user’s instruction from the page’s content. If a webpage can contain the malicious prompts, both are passed together to the AI model, which enables the attackers to hijack the AI assistant and force it to perform harmful actions with the user’s personal data.
Instead of easily summarising the page, this AI followed hidden instructions, which navigated to Gmail, retrieved a one-time password, and revealed the identity of the attackers in the comment thread. The AI agent has access to everything inside the users’ browsers, from Gmail to bank accounts. It can be easily manipulated with nothing more than a misleading prompt with natural language to report some of the hidden instructions.
Project Mariner AI agent across its products, rather than embedding it directly into Chrome, the risk of prompt injection is quite huge, and it remains one of the biggest challenges in the AI security field. Brave’s team reported the issue to Perplexity in July 2025, and the Comet browser was patched within a few days. According to the Brave, the prompt injection for the misleading instruction Perplexity’s Comet has not fully lit up.









