logo

CommetJacking attack tricks Comet browser into stealing emails

ID: 02b4a479-4f45-52ec-8036-33cbe7be56ea

STIX ID: report--02b4a479-4f45-52ec-8036-33cbe7be56ea

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2025-10-03

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

LayerX researchers disclosed a prompt-injection method called "CometJacking" that abuses the Comet AI browser's URL 'collection' parameter to deliver hidden instructions causing the agent to access connected services (such as Gmail and Google Calendar) and exfiltrate sensitive data (encoded in base64) to an attacker-controlled endpoint; Perplexity reviewed the reports and classified them as not applicable, and the proof-of-concept demonstrates a realistic, low-interaction data-exfiltration risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.