logo

PleaseFix Flaw Lets Hackers Access 1Password Vault via Comet AI Browser

ID: d695eb87-970a-5ed1-9642-9fc8bc94e8da

STIX ID: report--d695eb87-970a-5ed1-9642-9fc8bc94e8da

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Zenity Labs disclosed "PleaseFix," a family of zero-click indirect-prompt-injection flaws in Perplexity's Comet AI browser where a malicious calendar invite can cause the agent to browse local files and exfiltrate data or open and hijack an unlocked 1Password vault; Perplexity implemented hard boundaries and opt-in protections and Zenity confirmed the attacks were mitigated as of 13 February 2026, though opt-in settings leave residual risk to users who do not enable protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.