28.1 C
Delhi
Tuesday, March 3, 2026

AI Browser Security Warning: Critical Vulnerabilities Found in Comet and Atlas

AI Browser Security Alert: Researchers Uncover Critical Vulnerabilities

Security researchers have uncovered critical vulnerabilities in popular AI-powered browsers like Perplexity’s Comet and OpenAI’s ChatGPT Atlas that could allow hackers to hijack AI assistants and perform unauthorized actions using users’ logged-in privileges.

Key Security Risks Identified

  • Indirect prompt injection attacks can hijack AI assistants
  • Hidden commands embedded in webpages or images trigger malicious actions
  • Attackers can bypass security parameters of multiple AI browsers
  • Vulnerability affects user privacy and account security

How the Attack Works

Brave researchers discovered that malicious websites can exploit a technique called ‘indirect prompt injection’ to hijack AI assistants. Hackers embed hidden commands within webpages, social media comments, or images that the AI mistakenly interprets as legitimate user instructions.

“An attacker embeds malicious instructions in Web content that are hard to see for humans. In our attack, we were able to hide prompt injection instructions in images using a faint light blue text on a yellow background. This means that the malicious instructions are effectively hidden from the user,” Brave explained in their blog post.

Multiple Browsers Affected

The security flaw isn’t limited to Perplexity’s Comet. Researchers also bypassed security parameters in another AI browser called Felou. When users ask the browser to visit a website, it sends the site’s content to its language model, potentially including hidden malicious commands.

“The security vulnerability we found in Perplexity’s Comet browser this summer is not an isolated issue. Indirect prompt injections are a systemic problem facing Comet and other AI-powered browsers,” Brave warned.

OpenAI’s Awareness of Risks

Even OpenAI acknowledged the security challenges during the launch of ChatGPT Atlas. “Despite all of the power and awesome capabilities that you get with sharing your browser with ChatGPT, that also poses an entirely new set of risks,” an OpenAI employee admitted during the live-stream.

While OpenAI states that Atlas cannot access computer data beyond browser tabs, the company hasn’t clarified specific protections against prompt injection attacks. Some users already report that Atlas may be vulnerable to similar security flaws as Comet.

Latest

Tony Fadell says iPod is back as users have again started using it

Tony Fadell says the iPod is quietly making a comeback as users rediscover the distraction-free music player. Instead of streaming apps, many are turning to old

Beats launches special MagSafe cases for iPhone 17e, most affordable member of Apple’s iPhone 17 series

As Apple launched the iPhone 17e, Beats has rolled out new cases for the most affordable member of iPhone 17 series, making use of one of its big USP features:

Alibaba launches Qwen 3.5 small model series, beats ChatGPT and Gemini, even Elon Musk is impressed

Alibaba has launched four compact Qwen 3.5 models (0.8B to 9B), claiming the top 9B variant delivers performance close to much larger systems powering tools lik

IPhone 17e launched: India price, full specs, top features and how it compares to iPhone 17

Apple has launched the iPhone 17e in India as the most affordable model in the iPhone 17 line-up, bringing the new A19 chip, a 48MP camera and MagSafe at a lowe

‘Not worth it’: OpenAI scientist slams US Military AI deal as users rush to cancel ChatGPT

OpenAI research scientist Aiden McLaughlin has claimed that the AI startup should not have made the deal with the Pentagon. His comments come at a time when use

Topics

Odisha Board 10th Result 2026: BSE Odisha to announce Class 10 results likely by May second week

The Board of Secondary Education, Odisha, will likely announce...

US Embassies in Saudi, Kuwait, Bahrain, Jordan shut as Iran conflict escalates

The United States has closed multiple embassies and ordered the evacuation of non-emergency personnel across parts of the Gulf after Iranian drone attacks targe

Magnitude 4.3 earthquake hits Iran’s Gerash amid escalating Israeli-US attacks

The earthquake comes amid raging regional hostilities as the US and Israel have escalated attacks against Iran. There were no immediate reports of significant d

India trims gas supply to industries after Qatar halts LNG production

Qatar halted its LNG production on Monday as Iran continued strikes in the Gulf in response to Israeli and US attacks. The situation has disrupted energy shipme

The Kerala Story 2’s illegal broadcast by cable operators barred by Madras HC

The Kerala Story was released in theatres on Saturday after the Kerala High Court lifted a stay on its release.

China’s HQ-9B air defence fails twice in a year: After Op Sindoor, it’s Iran now

China's HQ-9B air-defence system, advertised as a flagship military hardware, is now under scrutiny after apparent failures in Iran and Pakistan, raising questi

Tony Fadell says iPod is back as users have again started using it

Tony Fadell says the iPod is quietly making a comeback as users rediscover the distraction-free music player. Instead of streaming apps, many are turning to old

Hero retains top spot in February sales as Honda narrows gap

India’s two-wheeler market clocked strong double-digit growth in February 2026, led by Hero MotoCorp, which stayed ahead of Honda Motorcycle & Scooter India i
spot_img

Related Articles

Popular Categories

spot_imgspot_img