Executive Summary
In October 2025, cybersecurity researchers uncovered a significant prompt injection attack targeting Perplexity's Comet AI browser. Dubbed "CometJacking," this incident involved adversaries embedding malicious prompts in links, which—when clicked by users—triggered unauthorized data siphoning through the browser's agentic AI capabilities. Sensitive information, including from connected services like email and calendars, was exposed, demonstrating how AI-driven interfaces can be subverted via crafted input. The attack exploited trust in browser automation and the deep integration of third-party services, raising concerns about the security of AI-powered productivity tools.
This incident is highly relevant as prompt injection attacks are rapidly emerging as a primary risk vector for generative AI environments. The growth in agentic AI and interconnected browser-based workflows has exposed new attack surfaces, prompting urgent calls for improved input validation, isolation of automation agents, and strengthened compliance for AI SaaS applications.
Why This Matters Now
Prompt injection attacks against agentic AI platforms are escalating, exposing a major gap in existing access controls and input validation. As organizations accelerate AI adoption, the risk of data loss and shadow AI activity increases, demanding rapid advancements in AI security and regulatory compliance practices.
Attack Path Analysis
The attacker initiated their attack by crafting a malicious link exploiting prompt injection, tricking the user into clicking and triggering unauthorized command execution within the Comet AI browser. Upon initial execution, the malicious prompt gained elevated access to underlying browser-connected services, possibly escalating privileges by leveraging misconfigured permissions or identity tokens. The attacker then laterally moved within the application, accessing sensitive user data from other integrated services. Maintaining communication channels, the attacker established covert command and control by executing additional prompts or scripts through the browser. Data exfiltration then occurred, with sensitive information siphoned from the browser or cloud services over unmonitored outbound connections. The impact included exposure or theft of private data, potentially leading to broader breaches or privacy violations.
Kill Chain Progression
Initial Compromise
Description
Victim clicks a malicious link embedding a prompt injection payload, enabling adversary control over the Comet AI browser session.
Related CVEs
CVE-2025-64496
CVSS 8.6A prompt injection vulnerability in Perplexity's Comet AI browser allows attackers to execute arbitrary commands by embedding malicious instructions in web content, leading to unauthorized actions and data exfiltration.
Affected Products:
Perplexity Comet AI Browser – up to 0.6.34
Exploit Status:
exploited in the wildReferences:
https://www.techradar.com/pro/security/this-webui-vulnerability-allows-remote-code-execution-heres-how-to-stay-safehttps://www.gadgets360.com/ai/news/perplexity-comet-ai-browser-vulnerable-to-prompt-injections-hacking-brave-browser-study-9497570https://www.theregister.com/2025/08/20/perplexity_comet_browser_prompt_injection/
MITRE ATT&CK® Techniques
Spearphishing Link
User Execution: Malicious Link
Prompt Injection
Unsecured Credentials
Input Capture: Web Portal Capture
Transfer Data to Cloud Account
Automated Exfiltration
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Secure Transmission of Account Data
Control ID: 3.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21(2)
CISA Zero Trust Maturity Model 2.0 – Application and User Authentication
Control ID: Identity Pillar, Control: Application Access Management
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI browser prompt injection attacks threaten software development environments, potentially exposing source code, API keys, and development workflows through compromised agentic AI tools.
Financial Services
CometJacking attacks can infiltrate email and calendar systems containing sensitive financial data, client information, and trading communications, violating compliance requirements like PCI DSS.
Legal Services
Attorney-client privileged communications accessed through compromised AI browsers pose severe confidentiality breaches, potentially exposing case strategies and sensitive legal document contents.
Health Care / Life Sciences
Prompt injection attacks targeting healthcare AI systems risk exposing patient records, research data, and HIPAA-protected information through compromised email and calendar integrations.
Sources
- CometJacking: One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thiefhttps://thehackernews.com/2025/10/cometjacking-one-click-can-turn.htmlVerified
- This WebUI vulnerability allows remote code execution - here's how to stay safehttps://www.techradar.com/pro/security/this-webui-vulnerability-allows-remote-code-execution-heres-how-to-stay-safeVerified
- Perplexity’s Comet AI Browser Is Vulnerable to Prompt Injections, Says Bravehttps://www.gadgets360.com/ai/news/perplexity-comet-ai-browser-vulnerable-to-prompt-injections-hacking-brave-browser-study-9497570Verified
- Perplexity's Comet browser faced prompt injection vulnhttps://www.theregister.com/2025/08/20/perplexity_comet_browser_prompt_injection/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west security, egress controls, and real-time threat detection would have significantly limited the ability of a malicious prompt injection to escalate, move laterally, and exfiltrate sensitive data through the Comet AI browser. CNSF-aligned controls could detect anomalous traffic flows, enforce least-privilege boundaries between browser sessions and cloud workloads, and prevent unauthorized outbound communications.
Control: Multicloud Visibility & Control
Mitigation: Early detection of suspicious inbound traffic or anomalous browser requests.
Control: Zero Trust Segmentation
Mitigation: Enforced identity-based least privilege boundaries block unauthorized access.
Control: East-West Traffic Security
Mitigation: Prevents unauthorized internal traffic between workloads or services.
Control: Threat Detection & Anomaly Response
Mitigation: Anomaly detection flags and interrupts covert command activity.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data extraction attempts are blocked or logged and alerted.
Autonomous policy enforcement confines attack blast radius and enables fast containment.
Impact at a Glance
Affected Business Functions
- Email Communications
- Calendar Management
- Data Storage
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive emails, calendar events, and stored credentials due to unauthorized access facilitated by the prompt injection vulnerability.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate browser workloads from connected cloud services, enforcing least privilege access.
- • Deploy East-West Traffic Security policies to restrict unauthorized lateral movement between SaaS, browser, and backend applications.
- • Enforce rigorous egress controls with FQDN filtering to block shadow AI exfiltration attempts and monitor outbound data flows.
- • Enhance real-time Threat Detection & Anomaly Response to rapidly flag and contain suspicious prompt behaviors and abnormal commands.
- • Centralize Multicloud Visibility & Control to proactively observe, baseline, and audit cloud-deployed AI and SaaS browser interactions.



