Reddit post hijacked Perplexity's Comet browser agent
Brave showed the agent reading a user's email for a one-time code and handing it to the attacker. Perplexity's first fix did not fully work.
By The Agentic Times ·

Perplexity's Comet browser could be turned against its user by ordinary text on a web page, Brave's security team disclosed in August 2025. When a user asked Comet to summarise a Reddit thread, instructions hidden in a comment made the agent open the user's Perplexity account page, read a one-time login code from their Gmail, and post both to the attacker's thread.
Brave, which was preparing its own browser agent at the time, said the core problem was that Comet fed page content directly to the model alongside the user's request, with no distinction between the two. Anything on a page the agent visited could therefore issue commands with the user's full logged-in privileges.
The company reported the issue to Perplexity in late July. It said Perplexity's initial fix was incomplete when Brave retested, and confirmed a working mitigation shortly before publishing. Perplexity did not dispute the findings.
Brave used the disclosure to argue for design rules for browser agents: page content should always be treated as untrusted, agents should confirm before sensitive actions, and agentic browsing should be isolated from normal sessions so that the agent does not automatically inherit every login.
Comet was one of the first mainstream browsers with a built-in agent, and the report was followed by further research into similar browsers from OpenAI and others over the following months.
Sources
- brave.comhttps://brave.com/blog/comet-prompt-injection/
