Editorial illustration for Perplexity Patches BrowseSafe After Brave Reveals Comet Security Flaw
Perplexity BrowseSafe Patches Critical AI Security Flaw
Perplexity's BrowseSafe patches agent gaps after Brave finds Comet flaw
In August 2025, Brave exposed a quiet but devastating flaw in Comet: hidden commands, buried in web pages and comments, that tricked AI assistants into handing over sensitive data. The technique, indirect prompt injection, turned everyday browsing into a covert extraction tool. Email addresses, one-time passwords, all quietly stolen.
That was the wake-up call. Perplexity saw that existing safety tests, like AgentDojo, were no match for the real world. Simple “ignore previous instructions” prompts?
Hardly. The chaos of actual websites, cluttered, noisy, adversarial, offers endless hiding spots for attackers. So Perplexity built BrowseSafe Bench.
A new standard, defined not by sterile simulations but by three concrete dimensions of real-world attack. It’s a direct attempt to patch the gaping holes in AI browser agents before the next exploit hits.
The severity of the issue became clear in August 2025, when Brave discovered a security vulnerability in Comet.
This is not a patch, it is a posture shift. Perplexity's BrowseSafe Bench finally acknowledges what Brave's Comet discovery made undeniable: the web is a war zone, and AI agents have been walking through it blind. Simple prompt hijacking was just the opening gambit.
The real threat lives in the tangled mess of authentic content, comments, footnotes, buried metadata, where a single hidden instruction can reroute trust. Three dimensions. One hard truth: safety cannot be measured by toy benchmarks that sanitize the chaos.
It must be forged in the noise. BrowseSafe is a bet that security can scale with complexity, not run from it. The Comet flaw wasn't the end of a story.
It was the beginning of a new standard.
Common Questions Answered
How did Brave uncover the security vulnerability in Perplexity's BrowseSafe product?
Brave discovered a critical security flaw using an indirect prompt injection technique where attackers could hide commands in web pages or comments. The method allowed potential manipulation of AI assistants to misinterpret hidden commands as user instructions, potentially enabling sensitive information theft.
What specific risks does the indirect prompt injection technique pose for AI assistants?
The indirect prompt injection technique can trick AI assistants into revealing sensitive personal information like email addresses and one-time passwords. By embedding hidden commands in web content, attackers could potentially manipulate AI systems into performing unintended actions or disclosing confidential data.
How quickly did Perplexity respond to the security vulnerability in Comet?
Perplexity quickly rushed to patch the security vulnerabilities after Brave's discovery of the critical flaw in their BrowseSafe product. The swift response underscores the growing awareness and importance of addressing potential security risks in AI systems.
Further Reading
- Perplexity's BrowseSafe tries to patch the gaping security holes inherent in AI browser agents — The Decoder
- BrowseSafe: Understanding and Preventing Prompt Injection Within Open-World Web Environments — Perplexity AI Research
- Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet — Brave
- Researchers Warn of Security Gaps in AI Browsers — Infosecurity Magazine
- The Browser Security Trilemma of 2025: How Perplexity Comet, Chrome, and Oasis Rewrote the Risk Equation — Kahana