/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail systemic vulnerabilities in AI agentic browsers, including Perplexity's Comet and Fellou, related to indirect prompt injection attacks

Building on our previous disclosure of the Perplexity Comet vulnerability, we've continued our security research across the agentic browser landscape.

Brave

Context & Ripple Effects

This extends Brave’s earlier report of a now-fixed Comet prompt-injection flaw from a single product issue to a broader agentic-browser security question. That matters as Comet, Fellou and other AI-first browsers compete for users alongside established browser platforms.

The findings arrive during an intensifying contest among AI-enhanced browsers, where product differentiation increasingly depends on agents acting for users rather than merely summarizing pages.

First-order effects

  • Comet, Fellou and other affected agentic-browser developers face immediate pressure to investigate indirect prompt-injection paths and tighten the controls governing browser actions.
  • Users and organizations evaluating these browsers must treat content encountered on the web as potentially untrusted input when an agent can act on their behalf.

Second-order effects

  • Browser rivals marketing autonomous assistance will need to show that their permissions, confirmation flows and isolation measures limit what malicious page content can induce an agent to do.
  • Security testing shifts from model-output quality toward end-to-end agent behavior: the relevant risk is the combination of web content, agent instructions and privileged browser actions.

Third-order effects

  • If similar findings persist across products, agentic browsers may be judged less by their ability to complete tasks than by whether they enforce a durable authorization boundary between untrusted content and user-authorized actions.
  • The pattern could push the category toward more constrained agent permissions and clearer user approval gates, though the supplied coverage does not establish which technical design will prevail.

The trend: As browsers become delegated-action interfaces, indirect prompt injection is becoming a core product-security and trust challenge rather than an isolated model-safety defect.

Discussion

  • @andreworlowski Andrew Orlowski on x
    This is really beautiful. Because an LLM can't distinguish between content and code, you can instantly kill an AI Browser by hiding a few lines of mischievous instruction on your web page. All that money invested in such a dumb technology.
  • @marktluszcz Mark Tluszcz on x
    You've been warned👇
  • @rahulsood @rahulsood on x
    Be *very* careful with Agentic browsers. I'm definitely not a fan of connecting my passwords or password manager to an AI that can get fooled by a website.
  • @kendude_ @kendude_ on x
    Yeah, I'm good. AI browsers are cool, but I'm not ready to give the wheel to a bot that could follow hidden instructions placed by hackers.
  • @shantanugoel Shantanu Goel on x
    Agentic browsers are a big attack vector, the surface area exposure being huge and security for them is still at a nascent stage and evolving. Don't use them at least as your primary browser. Or for anything that you have log in to or need to share sensitive data for.
  • @brendaneich @brendaneich on x
    With JS, I had to invent the Same Origin Policy in a hurry. OCap design ideas in “JS, the Good Parts” saved much of the day. My OWASP USA 2012 talk: https://www.slideshare.net/... AI browsers now let web content violate security policies. @Brave is on the case. https://brave.com/…
  • @jubal_hardin Jubal Hardin on x
    Seems important evidence of poor design. 🤔 “Indirect prompt injection attacks occur when malicious instructions are hidden in web content like webpages. When an LLM analyzes the content, it obeys the hidden instructions because it believes they're real commands from the user.”
  • @notschmee Tim Burton on x
    We've moved from prompt engineering to context engineering, and now we need the security layer. Context injection attacks demand the same defensive rigor as SQL injection once did.
  • @enlamp @enlamp on x
    the dawn of vibe hacking, using prompt-aware browsers as attack vector... not sure about the end-user benefits.
  • @santoshpanda Santosh Panda on x
    Browser: You control (to a large extent) AI Browser: AI controls - what if they go out of control? Not just Comet, but also Atlas or any other... It's very early days to give access to your Prime accounts.
  • @david_shane David Shane on x
    Well there's a new problem.
  • @mattfarina Matt Farina on x
    This feels like an opportunity to use prompts to Rick Roll people
  • @homammalk Homam on x
    Not sure how we're gonna solve this just yet but agentic browsers are wildly vulnerable to prompt injection. A site can literally embed hidden instructions anywhere in the page and hijack the agent's flow. Feels like an agent needs guardrails that look something like:
  • @xenosking @xenosking on x
    Props to Brave for working with these bowser companies to expose and fix these vulnerabilities. Even though they are competitors. RESPECT
  • @teortaxestex @teortaxestex on x
    This is Fine in the long run. Browsers for clankers are not browsers for citizens and their credentials. Ideally, they will be hardlocked into a separate system of APIs and a wholly segregated Clankernet. The back section of the World-Wide Bus. [image]
  • @koltregaskes @koltregaskes on x
    Be careful with these AI browsers, prompt injections are a real threat. [image]
  • @m4rio_eth @m4rio_eth on x
    prompt injection at the browser level! new attack vector. basically both comet from Perplexity and Atlas from OpenAI can be used to prompt inject by hidden content in the web pages
  • @brave @brave on x
    Indirect prompt injection attacks occur when malicious instructions are hidden in web content like webpages. When an LLM analyzes the content, it obeys the hidden instructions because it believes they're real commands from the user.
  • r/apple r on reddit
    OpenAI set to unveil AI browser with ChatGPT integration [U: Now available]