Join our Newsletter — 33% off our NHI Course

Comet URL prompt injection: what it means for browser identity risk

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: A crafted URL alone can trigger Perplexity’s Comet browser to read from memory, pull connector data such as Gmail and Calendar content, and exfiltrate it after trivial encoding, without credential theft or malicious page content, according to LayerX Security. That breaks the assumption that an authenticated assistant stays user-directed once a session begins, and it widens browser identity risk across NHI, agentic AI, and human programmes.

Editorial analysis by NHI Mgmt Group, based on content published by LayerX Security: “Is Perplexity Comet Safe? LayerX Finds a Prompt Injection Attack Vector”.

By the numbers:

  • LayerX Security submitted its findings to Perplexity under Responsible Disclosure guidelines on 27 August, 2025.

Key questions

Q: What breaks when an AI browser treats URL text as instructions?

A: The browser stops behaving like a passive navigation tool and starts acting on attacker-supplied prompts.

Q: Why does connector access make browser prompt injection more dangerous?

A: Because the assistant can move from public page content into authenticated services such as email and calendar.

Q: How do security teams detect whether AI browser exfiltration controls are failing?

A: Look for two signals: assistants that can pivot from navigation to memory-backed retrieval, and outbound payloads that only escape after simple transformation such as encoding.

Practitioner guidance

  • Map assistant instruction channels Identify where browser assistants accept URL parameters, query strings, or other untrusted text as instructions, and separate those paths from ordinary navigation handling.
  • Constrain memory-backed retrieval Review which assistant actions can switch from page context to stored memory or connector data, then restrict that pivot wherever it is not required for the use case.
  • Test encoded exfiltration paths Validate exfiltration controls against base64 and other simple transformations, because content filters that only inspect plain text will miss attacker-obfuscated outputs.

Bottom line: AI-native browsers can turn a crafted URL into an instruction channel, which breaks the assumption that navigation input and assistant commands are separate.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 18 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Browser identity now includes instruction integrity, not just authentication state: a logged-in AI browser can be redirected if the assistant accepts attacker-controlled URL parameters as task input. That means the control problem is no longer limited to who signed in, but to whether the assistant can distinguish navigation from instruction. Practitioners should treat browser-side prompt acceptance as part of identity governance, not a UX edge case.

A few things that frame the scale:

  • 43% of security professionals are concerned about AI systems learning and reproducing sensitive information patterns from codebases, according to the State of Secrets in AppSec.

A question worth separating out:

Q: What should teams do when browser assistants have access to email and calendar connectors?

A: Apply least-privilege scoping to each connector, review whether the assistant truly needs access for every task class, and remove any connector reach that is not essential. The goal is to narrow the assistant’s blast radius before prompt injection can turn delegated access into disclosure.

👉 Read our full editorial: AI browser prompt injection turns Comet into a data exfiltration path


This post was modified 18 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.