# AI Browsers Fall for Phishing: Perplexity's Comet Exploited in Minutes


Researchers have demonstrated a critical vulnerability in autonomous AI browser technology, successfully tricking Perplexity's Comet browser into executing a phishing attack in less than four minutes. The proof-of-concept reveals a troubling blind spot in emerging agentic AI systems: their capacity to be manipulated into compromising their users' security despite sophisticated machine learning architectures.


The discovery raises urgent questions about the safety of AI-powered web automation tools that are increasingly marketed as productivity enhancements. As these browsers gain adoption in both enterprise and consumer markets, the attack surface they expose deserves serious scrutiny from security teams and technology vendors alike.


## How Agentic AI Browsers Create New Attack Vectors


Autonomous web browsers powered by artificial intelligence represent a significant departure from traditional user-controlled browsing. Tools like Perplexity's Comet are designed to independently navigate websites, interpret content, make decisions, and execute actions on a user's behalf. This automation promise—conducting research, filling forms, comparing products, and booking reservations without human intervention—comes with a substantial security cost.


The fundamental problem lies in the browsers' architecture. These systems operate by analyzing page content, understanding user intent, and executing actions across multiple websites in rapid succession. They must make autonomous decisions about what constitutes legitimate user requests versus malicious manipulation. Researchers have identified a gap in this decision-making framework that allows attackers to craft specially designed web pages that trick the AI into believing a phishing attack is actually a legitimate user-requested action.


## The Four-Minute Exploitation Window


The researchers' successful attack demonstrates remarkable speed and efficiency. In under four minutes, they constructed a phishing scenario that convinced Comet to execute a credential theft attack. The exploit leverages the browser's tendency to trust page content and follow apparent user instructions embedded in web design elements.


The attack methodology exploits several weaknesses working in concert:


Social engineering at scale: Rather than targeting individual users with convincing phishing emails, attackers can craft a single malicious webpage that autonomously deceives any AI browser that visits it.


Absent security context: The AI browser processes the attack without understanding the broader security implications of its actions, much like a human user might fall for a convincing fake login page.


Rapid action execution: The speed at which agentic browsers operate—combined with their autonomous decision-making—compresses the window available for security controls to intervene.


Trust in page content: These browsers are trained to interpret and act on page instructions, creating inherent vulnerability to websites that masquerade as legitimate services.


## Background: The Rising Tide of Agentic AI Systems


Agentic AI represents one of the most actively developed frontiers in artificial intelligence. Unlike chatbots that respond to explicit user prompts, agentic systems operate with greater autonomy, making decisions independently and executing multi-step tasks across systems and websites.


This shift mirrors the evolution from simple search engines to AI assistants, and from AI assistants to browser automation. Each step has expanded the scope of actions AI systems can perform without explicit human approval. Web browsers represent a particularly powerful vector because they can interact with virtually any website on the internet—accessing everything from financial accounts to corporate systems to social media platforms.


The vendor pitch is compelling: imagine an AI assistant that autonomously researches topics, fills out forms on your behalf, finds the best prices, and handles routine digital tasks. Organizations see productivity gains. Consumers appreciate convenience. But security researchers see an increasingly powerful attack surface.


## Real-World Implications Beyond the Lab


The researchers' demonstration was controlled, but the implications extend far beyond their proof-of-concept. Organizations deploying agentic AI browsers for business operations face several concrete risks:


Credential theft and unauthorized access: An attacker could craft a page targeting employees using Comet for research or transaction processing, potentially compromising corporate credentials or API tokens.


Data exfiltration: A compromised agentic browser operating with access to internal systems could autonomously extract sensitive data to attacker-controlled servers.


Lateral movement: An AI browser tricked into performing actions on compromised web pages could facilitate attacks against connected systems and resources.


Supply chain compromise: Organizations using agentic browsers to interact with vendors or third-party services could inadvertently introduce compromise into those partners' systems.


The attack vector is particularly dangerous because it requires no user interaction once the browser is configured. Unlike traditional phishing, which relies on a victim clicking a link or opening an attachment, an agentic browser might autonomously visit a malicious page as part of a normal research task.


## The Broader Vulnerability Landscape


This incident is not an isolated flaw in a single product. Rather, it exposes fundamental challenges in designing AI systems that operate autonomously in adversarial environments. Web-based attacks are inherently difficult to defend against because:


The attacker controls the information the AI processes. Web pages can present false context, misleading instructions, and convincing imitations of legitimate services.


The AI system must make decisions with incomplete information and without human oversight in real-time.


Traditional security controls designed for human users may not translate effectively to AI browser protection.


As agentic AI systems become more capable and widespread, threat actors will continue discovering and exploiting similar vulnerabilities across multiple platforms.


## What Organizations Should Do Now


Security teams should treat agentic AI browser deployments as high-risk activities requiring careful governance:


Implement strict access controls: Limit the websites agentic browsers can access and the actions they can perform. Use network segmentation to prevent compromised browsers from reaching sensitive internal systems.


Require explicit approval workflows: Rather than fully autonomous operation, consider hybrid approaches where significant actions require human confirmation.


Monitor browser activity continuously: Deploy logging and alerting to detect unusual patterns—particularly sudden credential usage or data transfers following browser interactions.


Maintain current threat intelligence: Work with vendors and security researchers to stay informed about emerging vulnerabilities in agentic AI tools you deploy.


Conduct security awareness training: Employees should understand that agentic browsers introduce new risks and that traditional security principles still apply.


Demand vendor transparency: Require detailed security documentation from browser vendors, including threat models, security testing results, and disclosure policies.


## HackWire Analysis


The Perplexity Comet incident marks an inflection point in the evolution of AI-assisted productivity tools. Agentic web browsers offer genuine value, but that value comes packaged with vulnerabilities that organizations have not yet developed mature defenses against. The four-minute exploitation window is particularly telling—it suggests this isn't an obscure edge case but a fundamental weakness in how these systems currently operate.


As AI capabilities advance, the tension between automation and security will only intensify. Organizations rushing to adopt agentic AI browsers for competitive advantage should pause to assess whether they have the security infrastructure and governance frameworks necessary to manage the risks these tools introduce. The researchers who discovered this vulnerability have performed a valuable service by demonstrating that autonomous AI systems, for all their sophistication, remain surprisingly vulnerable to social engineering at scale.