logo

Perplexity’s Comet Browser Breached Through Calendar Invite Attack

ID: 0781110c-a50f-520a-8ba6-eba47424d800

STIX ID: report--0781110c-a50f-520a-8ba6-eba47424d800

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-04

Date Updated: 2026-06-18

Author: Divya

...
...

Zenity Labs disclosed a critical vulnerability in Perplexity’s Comet agentic browser that let an attacker-crafted Google Calendar invite manipulate the agent into opening attacker-controlled pages, reading local files via file:// URLs, and exfiltrating contents by embedding them in request URLs; the flaw affected macOS, Windows, and Android, could be bypassed around an initial fix using view-source: URLs, and posed additional risk to unlocked 1Password extensions before patches were confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.