TL;DR: A zero-click flaw in Perplexity Comet can turn a routine calendar invite into local file access and silent exfiltration, exposing the limits of current agentic browser safeguards, according to Zenity Labs’ PerplexedBrowser disclosure. The trust boundary between user intent and untrusted input collapses once the browser agent can act autonomously on page content.
At a glance
What this is: This analysis examines a zero-click agentic browser flaw that lets routine calendar content trigger local file access and exfiltration through Perplexity Comet.
Why it matters: It matters because agentic browsers sit inside authenticated sessions and local trust zones, so IAM, PAM, and NHI teams need controls that constrain autonomous action, not just user clicks.
Context
Agentic browsers are software that can read content, decide what to do next, and act on behalf of a user. In PerplexedBrowser, Zenity shows that this behaviour becomes dangerous when an untrusted calendar invite can influence an autonomous browser workflow and reach local files without an explicit approval boundary.
The governance gap is simple but severe: traditional browser security assumes the user remains in control of each sensitive action. Once a browser agent can interpret content as instruction, that assumption breaks and the security model has to shift from page trust to action trust.
For identity teams, the issue is not only web exposure. It is the intersection of authenticated session access, local device reach, and delegated execution, which makes agentic browsers part of NHI governance even when the user remains human.
Key questions
Q: What breaks when an agentic browser is allowed to process untrusted content as instruction?
A: The trust boundary between page content and action execution breaks. A calendar invite, message, or embedded element can become a command source if the browser is permitted to infer intent and act without a separate approval gate. That is why agentic browsing needs explicit action boundaries rather than traditional page filtering alone.
Q: Why do agentic browsers create a different risk profile than traditional browser security models?
A: Agentic browsers collapse multiple actions into autonomous workflows, so a small injection can become command execution, data exfiltration, or persistence before normal controls react. Traditional sandboxing and extension monitoring assume human paced behavior and clearer intent, but MCP driven tool chaining can move at machine speed and evade controls that only watch single events.
Q: What signs show that an autonomous browser workflow is failing?
A: Look for browser actions that cross from content viewing into local file access, unexpected uploads, or external requests that do not match the user’s intended task. Late safety warnings, especially after a task has already advanced, are a sign that enforcement is happening too far downstream to be reliable.
Q: How should teams govern AI browsers that can access local files and authenticated sessions?
A: Treat them as delegated identity-bearing systems with bounded authority. Define which resources they may read, which actions they may take, and where approval is required before they can move from a web page into the endpoint or into enterprise services. Governance should focus on action scope, not browser features alone.
Technical breakdown
How calendar content becomes an execution path
Agentic browsers do not just render content. They parse page elements, infer user intent, and decide what action to take next. In this case, a calendar invite becomes an instruction surface, so the agent can follow embedded or induced directives instead of treating the invite as inert data. That is why the boundary between content and command matters more here than in a conventional browser. Once the browser is allowed to reason over untrusted input, any routine workflow can become a control channel for attacker influence.
Practical implication: treat untrusted page content as a potential command source and gate any autonomous action that can touch local resources.
Why file:// access changes the risk model
The dangerous step is not simply opening a page. It is allowing the agent to reach local file paths and then move data out through an external endpoint. That creates a bridge between web content and host-resident secrets such as documents, credentials, or tokens. Traditional browser sandboxing is designed to contain tabs, not to govern an AI-driven workflow that can decide to read files and continue executing. This is why hard isolation between web input and filesystem access is central to the problem.
Practical implication: separate browser-rendered content from local filesystem permissions so page processing cannot become host file access.
Why recognition is not the same as prevention
Zenity’s analysis shows that the browser may notice something is wrong only after the harmful workflow has already been committed. That creates a control gap between safety awareness and enforceable stop conditions. In agentic systems, a warning that arrives late is operationally weak because the action may already be in flight. The real design issue is whether the agent can be forced to pause, re-evaluate, or abort before it reaches a sensitive boundary. Without that, detection becomes post-exposure telemetry rather than prevention.
Practical implication: require pre-execution enforcement points for sensitive actions instead of relying on post-action safety prompts.
Threat narrative
Attacker objective: The attacker wants to convert a trusted browser task into stealthy access to local files and downstream secrets.
- Entry begins when attacker-controlled or manipulated calendar content is processed by the agentic browser as if it were part of the user’s task.
- Credential or resource access follows when the browser is induced to reach file:// resources and other local data under the user’s authenticated context.
- Escalation occurs as the agent silently exfiltrates sensitive local files to attacker-controlled endpoints while appearing to complete a legitimate workflow.
- Impact is full read access to local information, with potential exposure of secrets that can support wider account or system compromise.
Breaches seen in the wild
- Meta Muse agent hijack 2026: An undocumented Muse setting let local malware hijack Meta's personal AI agent, steal its authentication material and abuse user access.
- EchoLeak (Microsoft 365 Copilot) 2025: A crafted email could make Microsoft 365 Copilot leak data from its context with no click, a zero-click prompt injection fixed as CVE-2025-32711.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Hard trust boundaries are the control that agentic browsers now lack: the browser can no longer be trusted to infer user intent from untrusted content and remain safe by design. Zenity’s disclosure shows that the dangerous unit of analysis is no longer the webpage or the click, but the autonomous action path. Practitioners should treat intent parsing itself as a security-sensitive operation.
The old browser security model assumed a human-paced decision loop: page content was something users interpreted, not something software executed against the local machine. That assumption fails when an agent can read a calendar invite, decide it is a task, and then move into local file access without a separate approval step. The implication is that identity and browser governance now have to constrain action boundaries, not just authentication.
Agentic browsers are becoming non-human identities with delegated reach: they sit inside user sessions, touch local resources, and act with a level of authority that traditional browser controls were never built to govern. That makes NHI governance relevant even when the end user is human, because the execution entity is not. The practical conclusion is that delegated browser authority has to be inventoried, bounded, and treated as a distinct identity surface.
Identity blast radius is the right concept for this class of exposure: one manipulated workflow can move from content processing to file access to secret disclosure in a single chain. The article shows that the blast radius is not limited to local documents, because exposed secrets can become footholds into cloud consoles, developer systems, and other authenticated services. Practitioners should assume that browser autonomy amplifies every credential already present on the endpoint.
Detection without enforcement is not enough for autonomous execution: Zenity notes that the browser could surface warning signals only after the workflow had already progressed. That means safety telemetry is useful, but not sufficient, when the system itself can keep acting. The field needs control points that can stop execution before sensitive boundaries are crossed, not just observe them after the fact.
What this signals
Agentic browser governance will converge with NHI controls: once a browser can act, it behaves less like a display surface and more like a delegated identity with local reach. That means access scope, session visibility, and action-level approval become the controls that matter, not just safe browsing policy.
Identity blast radius now extends from the endpoint to the enterprise: a single manipulated workflow can expose local secrets that later become cloud, code, or collaboration-system footholds. Practitioners should review where agentic browsers are allowed to operate and what sensitive material is resident on those endpoints.
Hard boundaries matter more than model confidence: the article shows that a system can recognise something is wrong only after the dangerous action has already started. For operational security, prevention has to sit before execution, especially where untrusted content and privileged sessions intersect.
For practitioners
- Define hard trust boundaries for agentic browser workflows Classify which browser actions may consume untrusted content, access local files, or trigger external network calls, then deny autonomous execution across those boundaries unless explicitly approved.
- Restrict local file system reach from browser agents Remove implicit access to file:// resources and other host-resident data from agentic browser contexts unless the workflow is separately authorised and scoped.
- Instrument pre-execution controls for sensitive actions Require an enforcement point before the agent can read, copy, upload, or transmit data so a warning does not arrive after exfiltration has already begun.
- Inventory autonomous browser identities and sessions Track where agentic browsers run, what authenticated sessions they hold, and which local or enterprise resources they can reach so the delegated authority is visible.
- Limit the secrets present on endpoints used by agents Reduce the value of endpoint theft by removing unnecessary credentials, tokens, and exports from devices that host agentic browsing activity.
Key takeaways
- The article shows that agentic browsers can collapse the boundary between routine content processing and local file access, creating a new class of autonomous-execution risk.
- The practical exposure is not limited to documents, because endpoint secrets and authenticated sessions can become stepping stones into wider enterprise systems.
- The control lesson is clear: security teams need hard boundaries and pre-execution enforcement for agentic browsing, not just warnings after the workflow starts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI02 — Tool Misuse | The browser is induced to use its tools and local reach against the user’s intent. |
| ASI03 — Identity & Privilege Abuse | The exploit abuses delegated browser authority inside authenticated sessions. | |
| Recommendation — Constrain autonomous browser tool use to explicit, pre-approved actions and block unsafe tool invocation. Limit agent identity scope and enforce approval before privileged actions are executed. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The browser acts with trust assumptions that are not safely bound to the user’s intent. |
| NHI-08 — Environment Isolation | The flaw crosses from untrusted web content into local filesystem access. | |
| Recommendation — Bind delegated browser actions to explicit authentication and re-validate before sensitive access. Separate untrusted content processing from local filesystem access with hard isolation controls. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | Agentic browser autonomy needs accountable governance over delegated action scope. |
| Recommendation — Define accountable governance for autonomous browser actions, approval boundaries, and escalation paths. | ||
| NIST Zero Trust (SP 800-207) | Continuous verification and least privilege | The attack shows why trust cannot be inherited from the browsing context. |
| Recommendation — Apply continuous verification and least privilege before allowing agentic browsers to cross trust boundaries. | ||
Key terms
- Agentic Browser: An agentic browser is a web browser with an embedded AI assistant that can interpret page content and take actions on the user’s behalf. It combines browsing, reasoning, and execution in one interface, which creates new governance requirements for identity, data handling, and approval boundaries.
- Shared Trust Boundary: A shared trust boundary is the point where multiple systems, teams, or identities rely on the same security controls and assumptions. It defines where trust is inherited rather than independently verified, so a weakness in one participant, credential, or control can affect others within that boundary.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Resource-Level Approval: A control model that assigns approval rules to the specific resource an automation or agent wants to change. It prevents teams from treating every action as equally safe. In practice, this means classifying each target by blast radius, then applying different approval requirements based on the sensitivity of the resource.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org