Security Issue with Comet AI Browser
The Comet AI browser, developed by Perplexity, has been found to have a significant security vulnerability. This issue allows an attacker to inject a prompt into the browser, giving them access to data in other open tabs.
What is the Vulnerability?
The vulnerability occurs when a user asks the Comet AI browser to summarize a web page. The Large Language Model (LLM) reads the web page, including any embedded prompts that command the LLM to take action on any open tabs. This means that an attacker can embed indirect prompt injection payloads into a web page, which the AI will then execute as commands.
How Does it Work?
According to Brave, the vulnerability lies in how Comet processes webpage content. When a user asks the browser to summarize a webpage, Comet feeds a part of the webpage directly to its LLM without distinguishing between the user’s instructions and untrusted content from the webpage. This allows attackers to gain access to sensitive information, such as emails or banking details, from other open tabs.
Attempts to Patch the Vulnerability
Perplexity attempted to patch the vulnerability, but unfortunately, the fix does not work. A post on Simon Willison’s Weblog confirmed that the issue still exists, leaving users vulnerable to attacks.
Reactions from the Community
The news of the vulnerability has sparked concern among users and developers. One developer posted on X, expressing their concerns about the security of AI browsers: "Why is no one talking about this? This is why I don’t use an AI browser. You can literally get prompt injected and your bank account drained by doomscrolling on reddit."
Conclusion
The security issue with the Comet AI browser is a significant concern for users. The vulnerability allows attackers to access sensitive information from other open tabs, making it a serious threat to user security. Until a proper fix is implemented, users should exercise caution when using the Comet AI browser, and consider alternative browsers that prioritize user security.