Perplexity’s Comet AI browser may have some security flaws that could let the hacker hijack your device


  • SquareX discovered hidden MCP API in the Comet browser that enabled arbitrary local command execution
  • Vulnerability in Agentic extension could let attackers hijack devices via compromised perplexity.ai site
  • The demo showed WannaCry execution; researchers warn that catastrophic third-party risk is inevitable

Cyber ​​security experts at SquareX claim to have found a major vulnerability in Comet, the AI ​​browser built by Perplexity, which could let threat actors take over the victim’s device completely.

SquareX found that the browser has a hidden API capable of executing local commands (commands on the underlying operating system, as opposed to just the browser).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top