The Containment Era is here. →Explore

Executive Summary

In October 2025, security researchers from LayerX uncovered a novel 'CometJacking' attack affecting Perplexity's Comet AI browser. This prompt injection attack leverages URL parameters to deliver hidden instructions that compel the browser to access and exfiltrate sensitive data—such as Gmail messages and Google Calendar information—from connected services, without any need for user credentials or interaction. The technique exploits the 'collection' URL parameter to insert malicious prompts, instructing the AI agent to gather and encode user data (e.g., using base64) before surreptitiously transmitting it to attacker-controlled endpoints. Despite being informed, Perplexity dismissed the security risk, highlighting concerns about unmitigated AI agent behaviors.This incident surfaces amid growing adoption of agentic AI browsers and illustrates the ease with which prompt injection tactics can sidestep controls, particularly in tools integrated with sensitive personal or enterprise accounts. The attack underscores the increasing threat from adversarial prompt engineering as AI agent usage expands rapidly.

Why This Matters Now

CometJacking demonstrates how generative AI systems, especially those with access to user accounts and services, can be exploited through prompt injection to steal sensitive data at scale. With AI browser adoption rising and safeguards lagging, organizations face urgent risks from unrecognized vectors that bypass conventional security controls.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

CometJacking is a prompt injection attack on the Perplexity Comet AI browser, where specially crafted URL parameters deliver malicious instructions that access and exfiltrate data from connected services.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying Zero Trust segmentation, egress policy enforcement, east-west traffic controls, and anomaly detection at the network and workload level could have constrained unauthorized data access and exfiltration initiated by prompt-injected instructions. Distributed CNSF would provide granular visibility and control to detect and block AI agent-driven data theft, even for encoded payloads.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Limits access at the application and service level, containing malicious prompts to least-privilege zones.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits the AI agent’s access scope to only intended, minimum-privilege targets.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Restricts lateral movement between workloads or service endpoints, reducing potential damage.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Blocks, alerts, or inspects anomalous outbound traffic to unauthorized destinations.

Exfiltration

Control: Threat Detection & Anomaly Response

Mitigation: Detects and alerts on abnormal data flows and patterns even when payloads are obfuscated.

Impact (Mitigations)

Limits downstream impact through distributed, inline enforcement and real-time incident containment.

Impact at a Glance

Affected Business Functions

  • Email Communications
  • Calendar Management
  • Data Security
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Unauthorized access to sensitive emails, calendar events, and potentially other personal data due to prompt injection vulnerabilities in the Comet AI browser.

Recommended Actions

  • Deploy Zero Trust Segmentation to limit AI browser access to only necessary connected services and data scopes.
  • Enforce strict egress controls and FQDN filtering to block unauthorized data flows from AI agents to external endpoints.
  • Implement anomaly-based threat detection to identify and respond to abnormal browser behaviors and covert exfiltration attempts.
  • Enhance monitoring and centralized visibility for all multi-cloud traffic, including agentic AI browsers and SaaS integrations.
  • Regularly review segmented privileges and application connectivity for AI-powered platforms to minimize potential attack surfaces.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image