Security researchers at SquareX have uncovered a critical security issue in the Comet AI browser, where an undocumented MCP API (chrome.perplexity.mcp.addStdioServer) allows embedded extensions to execute arbitrary local commands and launch applications on users' devices. This capability, which bypasses long-standing browser security controls, is not present in mainstream browsers like Chrome, Safari, or Firefox, and is largely undocumented, raising significant concerns about user trust and transparency. The API is accessible via the Agentic and Analytics extensions and can be triggered from the perplexity.ai page, creating a covert channel for device access without user consent or awareness.
Experts warn that this hidden API introduces a severe risk, as attackers could exploit it through compromised extensions, cross-site scripting (XSS), phishing, or insider threats, potentially granting full device control to malicious actors. The technical barrier for exploitation is low, and the feature's existence undermines established browser security principles. Enterprise security analysts note that this discovery reinforces the need for caution with AI browsers, which are already treated as unmanaged and high-risk applications in most organizations.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Following notification, Perplexity issued a silent update that disabled the MCP API in the Comet browser, effectively patching the reported issue. The fix addressed the immediate exposure, though concerns remained about transparency and hidden privileged browser components.
After validating the issue, SquareX reported the vulnerability to Perplexity. The disclosure prompted a vendor response over the hidden MCP API and its security implications.
Multiple security outlets publicly reported the hidden API issue in Comet, highlighting the risks of undocumented privileged browser features and the broader security model of AI browsers. Coverage emphasized that the incident could affect enterprise trust in agentic browsers and their system-level integrations.
SquareX showed that the undocumented Comet Analytics and Comet Agentic extensions could be abused through techniques such as extension stomping, malicious script injection, XSS, or man-in-the-middle scenarios. The demonstrated impact included malware installation, data theft, ransomware execution, and full device control.
SquareX researchers identified a critical design flaw in Perplexity's AI-powered Comet browser: hidden built-in extensions exposed an MCP API that could be abused to execute arbitrary commands on a user's device. The issue meant attackers who could compromise trusted browser-controlled contexts could potentially gain system-level access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcehelpnetsecurity.com
Open sourcesecurityonline.info
Open sourcehackread.com
Open sourcecsoonline.com
Open sourcesecuritysenses.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.