
The emergence of AI-enabled browsers, such as Perplexity's Comet and OpenAI's ChatGPT Atlas, marks a significant advancement in web technology. However, this innovation also introduces new security challenges, as highlighted in a recent report. Both Comet and Atlas are designed to handle multi-step actions on behalf of users, enhancing convenience but raising concerns over potential security vulnerabilities. Brave, a Chromium-based browser, has been particularly vocal about the risks associated with these so-called agentic AI browsers. In a previous investigation, Brave researchers uncovered a serious security flaw in Comet that could allow malicious websites to take control of the AI assistant, executing unauthorized tasks. This vulnerability, known as ‘Indirect prompt injection,’ enables attackers to embed hidden commands within web content, which the AI interprets as user instructions. The implications of this flaw are alarming. The report indicates that Comet allows users to take screenshots of websites and ask questions based on those images. However, attackers have been found to inject malicious prompts by embedding nearly invisible text within these images. As Brave explains, “An attacker embeds malicious instructions in Web content that are hard to see for humans,” posing a significant risk to unsuspecting users. In tests, Brave demonstrated how attackers could manipulate the AI assistant into executing harmful commands by cleverly disguising their instructions. Furthermore, researchers also identified vulnerabilities in another AI browser, Felou, revealing that it could inadvertently send both user commands and malicious instructions to its large language model (LLM). Brave warns that the vulnerabilities found in Comet are not isolated incidents, but rather indicative of a broader issue affecting multiple AI-enabled browsers. OpenAI, recognizing these risks, acknowledged the potential dangers associated with its Atlas browser during its launch presentation. While OpenAI claims that Atlas only accesses browser tabs and not other computer data, it has not provided specific details on how it addresses the threat of prompt injections. With growing concerns over these vulnerabilities, some users have started to voice apprehensions on social media, suggesting that Atlas may share similar security weaknesses as Comet. As the AI browser landscape evolves, users must remain vigilant about the potential risks these advanced technologies may pose.
A groundbreaking solar-powered drone has been reported lost at sea following an astonishing eight-day flight that took p...
Ars Technica | May 13, 2026, 21:50
Elon Musk's xAI is currently operating nearly 50 natural gas turbines at its data center in Mississippi, a situation tha...
TechCrunch | May 13, 2026, 20:20
In a contentious move, the Federal Communications Commission (FCC) has given the green light for EchoStar to sell its sp...
Ars Technica | May 13, 2026, 20:45
In a year marked by significant advancements in artificial intelligence, Anthropic is positioning itself to potentially ...
TechCrunch | May 13, 2026, 19:55
In a bizarre twist to drug smuggling tactics, four Australian men attempted to use Xerox printers as a cover for traffic...
Ars Technica | May 13, 2026, 20:10