Brave reports that Comet passed webpage content to its assistant without separating it from user instructions, so hidden text on a page could direct the agent to act across the user's logged-in sites, including reading email-based login codes. Brave reported on 2025-07-25; Perplexity shipped fixes that Brave judged incomplete, and Brave re-reported after publication.
Why it matters
Agentic browsers act with the user's cookies, so page content can reach across sites that the same-origin policy normally separates.
Key facts
As stated in the sources, with where to find them.
- Timeline: reported 2025-07-25; initial fix 2025-07-27; fix deemed incomplete 2025-07-28; patching confirmed 2025-08-13; later testing indicated incomplete mitigation.Disclosure timeline
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Oct 21, 2025
Oct 8, 2025
Aug 6, 2025
Jul 8, 2025
Oct 31, 2025
Sep 25, 2025