Until last month, attackers could've stolen info from Perplexity Comet users just by sending a calendar invite
ID: e0ed0fc0-33b5-51fb-9e4a-42fb42f2e219
STIX ID: report--e0ed0fc0-33b5-51fb-9e4a-42fb42f2e219
Feed Name: The Register (Security)
Security researchers at Zenity Labs found that Perplexity's Comet AI browser could be induced via calendar-event prompt injection to open links and local file:// paths without user consent and — when a 1Password extension was installed and unlocked — could be instructed to visit extension URLs to take over a 1Password vault. The issue, demonstrated using malicious Google Calendar invites with hidden instructions, enabled local file access and potential full account takeover within an authenticated session; Perplexity released patches (with an interim bypass) and 1Password issued hardening guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
