Security researchers at Zenity Labs disclosed PleaseFix, a family of critical vulnerabilities affecting agentic browsers—including Perplexity’s Comet—that enable AI agent hijacking via indirect prompt injection embedded in routine workflows. In the Comet-specific PerplexedBrowser variant, attackers can trigger unauthorized agent actions inside an authenticated user session, including local file access and data exfiltration, while the agent continues to behave normally from the user’s perspective, reducing the chance of detection.
One demonstrated attack uses a poisoned Google Calendar invite: hidden content (e.g., whitespace-obscured elements and a system_reminder-style instruction block) is processed when a user asks Comet’s agent to handle the invite, causing an “intent collision” where the agent merges the user’s request with attacker instructions. The payload can drive background navigation to attacker-controlled infrastructure, bypass language-focused guardrails by switching languages (e.g., Hebrew), coerce the agent into reading sensitive file:// resources (configuration files, API keys), and exfiltrate data by embedding it into outbound requests. A second exploit path described by Zenity Labs abuses agent-authorized workflows to manipulate password-manager interactions—potentially enabling credential theft (including from an unlocked 1Password session) and account takeover without directly exploiting the password manager itself.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Zenity Labs publicly disclosed the PleaseFix family of agentic browser vulnerabilities, including the PerplexedBrowser issues in Perplexity's Comet browser. The disclosure described zero-click and low-interaction attack paths using indirect prompt injection in routine content such as calendar invites to access local files and steal credentials within authenticated sessions.
As of 2026-02-13, Zenity confirmed that the demonstrated attacks against Comet, including local file exfiltration and related exploit paths, were no longer effective. Researchers noted, however, that broader agent-steering risks remain and some protections are opt-in.
Perplexity implemented a code-level hard boundary preventing the Comet agent from accessing local file paths via file://, along with other mitigations such as options to disable AI behavior on sensitive sites. Zenity later said this second patch closed the demonstrated local-file exfiltration path.
Zenity Labs responsibly disclosed the PerplexedBrowser/PleaseFix issues affecting Perplexity's Comet browser to Perplexity, with multiple reports placing the disclosure on 2025-10-22. Perplexity reportedly classified the issue as critical.
After the initial disclosure, Perplexity issued an initial patch for the Comet browser flaw, but researchers said the fix could be bypassed. The incomplete remediation led to a second round of patching to fully block the demonstrated file:// access path.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcevulnu.com
Open sourcetechrepublic.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.