PleaseFix Flaw Lets Hackers Access 1Password Vault via Comet AI Browser
ID: d695eb87-970a-5ed1-9642-9fc8bc94e8da
STIX ID: report--d695eb87-970a-5ed1-9642-9fc8bc94e8da
Feed Name: HackRead
Threat Score
Zenity Labs disclosed "PleaseFix," a family of zero-click indirect-prompt-injection flaws in Perplexity's Comet AI browser where a malicious calendar invite can cause the agent to browse local files and exfiltrate data or open and hijack an unlocked 1Password vault; Perplexity implemented hard boundaries and opt-in protections and Zenity confirmed the attacks were mitigated as of 13 February 2026, though opt-in settings leave residual risk to users who do not enable protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
