Perplexity's Comet AI Browser Vulnerability Exposed Sensitive User Data
AI-Generated Summary
Perplexity's Comet AI browser was found to have a critical indirect prompt injection vulnerability, identified by Brave, that could expose users' sensitive data like emails, passwords, and banking information. The flaw allowed attackers to manipulate the browser's AI through embedded prompts on webpages, bypassing traditional security measures. Perplexity has since confirmed that the issue has been resolved.
In a nutshell
This incident underscores the novel and complex security challenges emerging with AI-powered browsers, where traditional web protections are inadequate against AI manipulation. It highlights the critical importance of secure-by-design principles and rigorous testing for AI agents that handle sensitive user data and perform autonomous actions.
Source: Livemint