TL;DR: A zero-click flaw in Perplexity Comet can turn a routine calendar invite into local file access and silent exfiltration, exposing the limits of current agentic browser safeguards, according to Zenity Labs’ PerplexedBrowser disclosure. The trust boundary between user intent and untrusted input collapses once the browser agent can act autonomously on page content.
Editorial analysis by NHI Mgmt Group, based on content published by Zenity: “PerplexedBrowser: Accepting a Meeting or Handing Your Local Files to an Attacker?”.
Key questions
Q: What breaks when an agentic browser is allowed to process untrusted content as instruction?
A: The trust boundary between page content and action execution breaks.
Q: Why do agentic browsers create a different risk profile than traditional browser security models?
A: Agentic browsers collapse multiple actions into autonomous workflows, so a small injection can become command execution, data exfiltration, or persistence before normal controls react.
Q: What signs show that an autonomous browser workflow is failing?
A: Look for browser actions that cross from content viewing into local file access, unexpected uploads, or external requests that do not match the user’s intended task.
Practitioner guidance
- Define hard trust boundaries for agentic browser workflows Classify which browser actions may consume untrusted content, access local files, or trigger external network calls, then deny autonomous execution across those boundaries unless explicitly approved.
- Restrict local file system reach from browser agents Remove implicit access to file:// resources and other host-resident data from agentic browser contexts unless the workflow is separately authorised and scoped.
- Instrument pre-execution controls for sensitive actions Require an enforcement point before the agent can read, copy, upload, or transmit data so a warning does not arrive after exfiltration has already begun.
Bottom line: The article shows that agentic browsers can collapse the boundary between routine content processing and local file access, creating a new class of autonomous-execution risk.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Hard trust boundaries are the control that agentic browsers now lack: the browser can no longer be trusted to infer user intent from untrusted content and remain safe by design. Zenity’s disclosure shows that the dangerous unit of analysis is no longer the webpage or the click, but the autonomous action path. Practitioners should treat intent parsing itself as a security-sensitive operation.
A question worth separating out:
Q: How should teams govern AI browsers that can access local files and authenticated sessions?
A: Treat them as delegated identity-bearing systems with bounded authority. Define which resources they may read, which actions they may take, and where approval is required before they can move from a web page into the endpoint or into enterprise services. Governance should focus on action scope, not browser features alone.
👉 Read our full editorial: PerplexedBrowser shows why agentic browsers need hard trust boundaries