"While looking at Comet, we discovered vulnerabilities which we reported to Perplexity, and which underline the security challenges faced by agentic AI implementations in browsers. The attack demonstrates how easy it is to manipulate AI assistants into performing actions that were prevented by long-standing Web security techniques, and how users need new security and privacy protections in agentic browsers.

The vulnerability we’re discussing in this post lies in how Comet processes webpage content: when users ask it to “Summarize this webpage,” Comet feeds a part of the webpage directly to its LLM without distinguishing between the user’s instructions and untrusted content from the webpage. This allows attackers to embed indirect prompt injection payloads that the AI will execute as commands. For instance, an attacker could gain access to a user’s emails from a prepared piece of text in a page in another tab."

https://brave.com/blog/comet-prompt-injection/

#AI #GenerativeAI #CyberSecurity #AgenticAI #Perplexity #PerplexityComet #PromptInjection

Reply to this note

Please Login to reply.

Discussion

Reminds of duping by injection of white text instructions on a white page of a PDF ingested into LLM prompt/RAG.