More

    ‘The attack requires no exploit, no user clicks, and no explicit request forsensitive actions’: Experts say Perplexity’s AI Comet browser can be hijacked to steal your passwords



    • Zenity researchers uncovered PleaseFix, a zero-click indirect prompt injection flaw in Comet browser
    • Malicious calendar invites could trick the AI into exfiltrating passwords and sensitive files without user awareness
    • Bug patched with restrictions on file:// access, preventing agents from reading local filesystem

    Perplexity’s AI-powered Comet web browser is vulnerable to indirect prompt injection attacks, which threat actors can exploit to exfiltrate sensitive data such as passwords, experts have warned.

    Security researchers Zenity dubbed the flaw PleaseFix, and demonstrated different ways in which it might be abused.


    https://cdn.mos.cms.futurecdn.net/Gu8XfetHGhnHJKVFvvXgm7-1920-80.png



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img