{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/brave-perplexity-comet-indirect-prompt-injection-2025/",
 "asOf": "2026-09-26",
 "id": "brave-perplexity-comet-indirect-prompt-injection-2025",
 "date": "2025-08-20",
 "datePrecision": "day",
 "title": "Brave discloses indirect prompt injection in Perplexity Comet agentic browser",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Brave reports that Comet passed webpage content to its assistant without separating it from user instructions, so hidden text on a page could direct the agent to act across the user's logged-in sites, including reading email-based login codes. Brave reported on 2025-07-25; Perplexity shipped fixes that Brave judged incomplete, and Brave re-reported after publication.",
 "whyItMatters": "Agentic browsers act with the user's cookies, so page content can reach across sites that the same-origin policy normally separates.",
 "actors": [
  "brave",
  "perplexity"
 ],
 "topics": [
  "prompt-injection",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "credentials",
  "tools"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://brave.com/blog/comet-prompt-injection/",
   "publisher": "Brave",
   "title": "Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet",
   "date": "2025-08-20",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Timeline: reported 2025-07-25; initial fix 2025-07-27; fix deemed incomplete 2025-07-28; patching confirmed 2025-08-13; later testing indicated incomplete mitigation.",
   "locator": "Disclosure timeline"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}