Security researchers at Brave found that Perplexity’s agentic Comet browser could be hijacked through indirect prompt injection: hidden instructions embedded in a Reddit post behind a spoiler tag caused the AI assistant to retrieve a one-time password from the user’s email and post it back where an attacker could capture it. The exploit let an attacker take over a victim’s Perplexity account after the user did nothing more than ask Comet to summarize the page. Perplexity’s initial fix was found to be incomplete when researchers retested it.