Perplexity’s Comet Browser Breached Through Calendar Invite Attack
ID: 0781110c-a50f-520a-8ba6-eba47424d800
STIX ID: report--0781110c-a50f-520a-8ba6-eba47424d800
Feed Name: GBHackers
Zenity Labs disclosed a critical vulnerability in Perplexity’s Comet agentic browser that let an attacker-crafted Google Calendar invite manipulate the agent into opening attacker-controlled pages, reading local files via file:// URLs, and exfiltrating contents by embedding them in request URLs; the flaw affected macOS, Windows, and Android, could be bypassed around an initial fix using view-source: URLs, and posed additional risk to unlocked 1Password extensions before patches were confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
