logo

Perplexity AI Browser Flaw Could Let Calendar Invites Access Local Files

ID: 72f231d2-402b-5475-9c00-9fdd73443bb2

STIX ID: report--72f231d2-402b-5475-9c00-9fdd73443bb2

Feed Name: TechRepublic Security

Threat Score
65/100

Date Published: 2026-03-04

Date Updated: 2026-04-23

Author: Kezia Jungco

...
...

Security researchers disclosed a PleaseFix class vulnerability in Perplexity’s Comet agentic browser that could let hidden prompts (for example, in calendar invitations) instruct the AI agent to access local file:// resources and exfiltrate documents and credentials while acting within authenticated sessions; Perplexity released patches after disclosure, including a second fix to block file:// access and close the demonstrated attack path.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.