2025-08-25
Why is no one talking about this? This is why I don't use an AI browser You can literally get prompt injected and your bank account drained by doomscrolling on reddit: [image]
Brave
Researchers detail a now-fixed flaw in Perplexity's Comet AI browser that let an attacker use an indirect prompt injection to manipulate it into taking actions
Brave and Guardio's security audits call out paid AI browser Victor Tangermann / Futurism : Using an AI Browser Lets Hackers Drain Your Bank Account Just by Showing You a Public Re...
No one seems to be concerned about this, it seems to me like the #1 problem with any agentic AI stuff You can get pwned so easily, all an attacker has to do is literally write words down somewhere???
Brave
Researchers detail a now-fixed flaw in Perplexity's Comet AI browser that let an attacker use an indirect prompt injection to manipulate it into taking actions
Brave and Guardio's security audits call out paid AI browser Victor Tangermann / Futurism : Using an AI Browser Lets Hackers Drain Your Bank Account Just by Showing You a Public Re...
Usually when you read a security vulnerability report it's usually a combination of some low-level shit like: “exploit a bug in the Linux kernel to get a use-after-free via a refcounting bug to overwrite a vtable pointer to-” Here it's literally “we wrote reddit comment then it [image]
Brave
Researchers detail a now-fixed flaw in Perplexity's Comet AI browser that let an attacker use an indirect prompt injection to manipulate it into taking actions
Brave and Guardio's security audits call out paid AI browser Victor Tangermann / Futurism : Using an AI Browser Lets Hackers Drain Your Bank Account Just by Showing You a Public Re...
Furthermore, it seems like very high profile and rich people and investors are trying out these AI browsers, seems like a really easy way to pwn someone with a lot of money: https://x.com/...
Brave
Researchers detail a now-fixed flaw in Perplexity's Comet AI browser that let an attacker use an indirect prompt injection to manipulate it into taking actions
Brave and Guardio's security audits call out paid AI browser Victor Tangermann / Futurism : Using an AI Browser Lets Hackers Drain Your Bank Account Just by Showing You a Public Re...