Researchers discover suite of agentic AI browser vulnerabilities
ID: c4f62f12-21e9-5cf9-9627-02469452ed09
STIX ID: report--c4f62f12-21e9-5cf9-9627-02469452ed09
Feed Name: CyberScoop
Threat Score
Zenity Labs disclosed prompt-injection vulnerabilities affecting agentic AI browsers (including Perplexity’s Comet) that allow attacker-controlled content—such as malicious calendar invites—to persuade autonomous agents to access local files, take over password managers, and exfiltrate secrets; Perplexity issued patches in February 2026, but researchers warn prompt-injection remains a fundamental and persistent risk for agentic browsers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
