CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

CometJacking attack exploits Comet browser to steal emails

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A new attack called CometJacking exploits URL parameters to pass hidden instructions to Perplexity's Comet AI browser, allowing access to sensitive data from connected services like email and calendar. The attack does not require credentials or user interaction. Comet is an agentic AI browser that can autonomously browse the web and manage tasks such as emails, shopping, and booking tickets. Despite known security gaps, its adoption is increasing. The CometJacking attack was discovered by LayerX researchers, who reported it to Perplexity in late August. Perplexity responded that it did not identify an issue, marking the report as 'not applicable.'

Timeline

  1. 03.10.2025 17:01 1 articles · 3h ago

    LayerX researchers discover CometJacking attack in Comet AI browser

    LayerX researchers discovered the CometJacking attack in late August 2025 and reported it to Perplexity. The attack exploits URL parameters to pass hidden instructions to the Comet AI browser, allowing access to sensitive data from connected services. Perplexity's security team rejected the reports, stating that the attack does not lead to any security impact.

    Show sources

Information Snippets