On websites they control, attackers might hide instructions using white text on white backgrounds, HTML comments, or other invisible elements. Alternatively, they may inject malicious prompts into user-generated content on social media platforms such as Reddit comments or Facebook posts. [...] The attack we developed shows that traditional Web security assumptions don't hold for agentic AI, and that we need new security and privacy architectures for agentic browsing.
Brave's own security team, building a browser agent of its own, tested Perplexity's Comet and found it would follow instructions planted in a Reddit comment. The chain they demonstrated is worth reading in full because nothing in it is exotic: the agent was told to open the user's Perplexity account page and read their email address, then to visit a lookalike domain (perplexity.ai. with a trailing dot, which browsers treat as a different host) to trigger a one-time password, then to open Gmail, where the user was already signed in, read the code, and post both back as a reply to the original comment. Every step used the user's existing logged-in sessions. Brave reported it to Perplexity before publishing.