Tools AI Risk Radar ai-incident-0073
Incident record
PerplexedBrowser: Perplexity Comet agent leaks local files via calendar-invite injection
- Severity
- High
- Status
- Patched
- Type
- Agent Hijack
- Target
- Perplexity Comet
- Actor
- researcher
What happened
Zenity Labs disclosed a flaw it called PerplexedBrowser in Perplexity's AI-powered Comet browser, in which instructions hidden in a calendar invitation could cause the browser agent to read files on the user's machine and send their contents to an external server. Perplexity shipped a fix restricting agent access to local file paths. The finding was a proof-of-concept with no reported real-world exploitation.
Sources
- eSecurity Planet (Zenity Labs)www.esecurityplanet.com/artificial-intelligence/perplexity-c…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026