logo

Obscure MCP API in Comet Browser Breaches User Trust, Enabling Full Device Control via AI Browsers

ID: 13ec9f0f-1bdb-5013-a02f-89f19798b46b

STIX ID: report--13ec9f0f-1bdb-5013-a02f-89f19798b46b

Feed Name: Security Ledger

Threat Score
78/100

Date Published: 2025-11-19

Date Updated: 2026-04-26

...
...

SquareX disclosed research showing the Comet AI Browser exposes an undocumented MCP API (chrome.perplexity.mcp.addStdioServer) that allows embedded extensions persistent, unrestricted local command execution. The team demonstrated an attack chain using extension-stomping and the Agentic extension to run WannaCry, noted embedded extensions are hidden from users and cannot be disabled, and warns this design creates severe third-party and supply-chain risk; SquareX calls for API disclosure, third-party audits, and user controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.