LogoAgentHunter
  • Submit
  • Industries
  • Categories
  • Agency
Logo
LogoAgentHunter

Discover, Compare, and Leverage the Best AI Agents

Featured On

Featured on yo.directory
yo.directory
Featured on yo.directory
Featured on Startup Fame
Startup Fame
Featured on Startup Fame
AIStage
Listed on AIStage
Sprunkid
Featured on Sprunkid
Featured on Twelve Tools
Twelve Tools
Featured on Twelve Tools
Listed on Turbo0
Turbo0
Listed on Turbo0
Featured on Product Hunt
Product Hunt
Featured on Product Hunt
Game Sprunki
Featured on Game Sprunki
AI Toolz Dir
Featured on AI Toolz Dir
Featured on Microlaunch
Microlaunch
Featured on Microlaunch
Featured on Fazier
Fazier
Featured on Fazier
Featured on Techbase Directory
Techbase Directory
Featured on Techbase Directory
backlinkdirs
Featured on Backlink Dirs
Featured on SideProjectors
SideProjectors
Featured on SideProjectors
Submit AI Tools
Featured on Submit AI Tools
AI Hunt
Featured on AI Hunt
Featured on Dang.ai
Dang.ai
Featured on Dang.ai
Featured on AI Finder
AI Finder
Featured on AI Finder
Featured on LaunchIgniter
LaunchIgniter
Featured on LaunchIgniter
Imglab
Featured on Imglab
AI138
Featured on AI138
600.tools
Featured on 600.tools
Featured Tool
Featured on Featured Tool
Dirs.cc
Featured on Dirs.cc
Ant Directory
Featured on Ant Directory
Featured on MagicBox.tools
MagicBox.tools
Featured on MagicBox.tools
Featured on Code.market
Code.market
Featured on Code.market
Featured on LaunchBoard
LaunchBoard
Featured on LaunchBoard
Genify
Featured on Genify
Copyright © 2025 All Rights Reserved.
Product
  • AI Agents Directory
  • AI Agent Glossary
  • Industries
  • Categories
Resources
  • AI Agentic Workflows
  • Blog
  • News
  • Submit
  • Coummunity
  • Ebooks
Company
  • About Us
  • Privacy Policy
  • Terms of Service
  • Sitemap
Friend Links
  • AI Music API
  • ImaginePro AI
  • Dog Names
  • Readdit Analytics
Back to News List

CometJacking Attack Hijacks Perplexity AI Browser to Steal User Data

October 5, 2025•The Hacker News•Original Link•2 minutes
Cybersecurity
AI
DataTheft

A malicious URL exploit turns Perplexity's Comet AI browser into a data thief, exfiltrating emails, calendar, and memory via encoded payloads.

Cybersecurity researchers have uncovered a new attack called CometJacking, which targets Perplexity's AI-powered browser, Comet. The attack leverages malicious prompts hidden within seemingly harmless links to siphon sensitive data, including emails, calendar entries, and user memory. This exploit bypasses Perplexity's security measures using Base64-encoding tricks, turning the AI browser into an unwitting data thief.

Comet AI Browser

How CometJacking Works

The attack unfolds in five steps:

  1. A victim clicks on a specially crafted URL, delivered via phishing or embedded in a webpage.
  2. Instead of navigating to the intended destination, the URL triggers Comet's AI to execute a hidden prompt.
  3. The AI captures data from connected services like Gmail and Calendar.
  4. The stolen data is obfuscated using Base64 encoding.
  5. The encoded payload is sent to an attacker-controlled endpoint.

Michelle Levy, Head of Security Research at LayerX, warned, "This isn't just about stealing data; it's about hijacking the agent that already has the keys." The attack exploits Comet's trusted status, as it already has authorized access to user accounts.

LayerX Research

Perplexity's Response and Broader Implications

Perplexity has dismissed the findings as having "no security impact," but experts argue that AI-native tools introduce new risks. Earlier this year, Guardio Labs revealed Scamlexity, a similar attack tricking AI browsers into interacting with phishing pages.

Or Eshed, CEO of LayerX, emphasized, "AI browsers are the next enterprise battleground." Organizations are urged to implement controls to detect and neutralize malicious prompts before widespread exploitation occurs.

For more details on the research, visit LayerX's report.

Follow The Hacker News for updates on emerging cybersecurity threats.

Related News

October 6, 2025•Dominic-Madori Davis

Heidi Health secures 65M Series B funding for AI medical scribe

Heidi Health raised 65 million in Series B funding led by Steve Cohens Point72 Private Investments to expand its AI medical scribe platform.

Healthtech
AI
Funding
October 6, 2025•Deutsche Telekom AG

Deutsche Telekom launches AI-phone Pro with advanced features

Deutsche Telekom introduces AI-phone Pro with Perplexity assistant and Picsart integration launching October 14

AI
Smartphone
DeutscheTelekom

About the Author

Dr. Sarah Chen

Dr. Sarah Chen

AI Research Expert

A seasoned AI expert with 15 years of research experience, formerly worked at Stanford AI Lab for 8 years, specializing in machine learning and natural language processing. Currently serves as technical advisor for multiple AI companies and regularly contributes AI technology analysis articles to authoritative media like MIT Technology Review.

Expertise

Machine Learning
Natural Language Processing
Deep Learning
AI Ethics
Experience
15 years
Publications
120+
Credentials
3
LinkedInTwitter

Agent Newsletter

Get Agentic Newsletter Today

Subscribe to our newsletter for the latest news and updates