Is Comet browser safe? What security research found

· · 9 min read

As of October 2026, the short answer to “is Comet browser safe?” is: it is reasonable to try for low-risk browsing, but do not give its agent unrestricted access to your logged-in email, bank, or password manager. That is my judgment from the published tests and vendor responses below, not a security certification. Researchers have shown ways to redirect browser agents through pages, links, screenshots, and ordinary workflows. Vendors have shipped fixes and defenses, but the class of attack is not closed.

Each disclosure is about a particular path, not proof that every current Comet build is exposed. The risk depends on what the agent can read and do.

What did security researchers find in Comet?

They found multiple ways for untrusted content to steer Comet’s agent, with possible access to data already available in the browser. These prompt injection examples and related tests span different triggers, so a fix for one path does not establish that all prompt injection is solved.

In August 2025, Brave described a page-summary attack it calls indirect prompt injection: a hidden Reddit comment could tell Comet to visit the user’s Perplexity account, read an emailed one-time code, and post it back. Brave’s final test on August 13 found the path “appears to be patched,” but an update added after publication says Perplexity “still hasn’t fully mitigated” this kind of attack and that Brave re-reported it. Brave’s August 2025 disclosure

In October 2025, Brave reported another path: nearly invisible instructions inside a screenshot could be read by Comet’s visual processing and treated as commands. That report records discovery and disclosure to Perplexity, but does not give a confirmed fix date. Brave’s October 2025 screenshot research

LayerX’s October 2025 “CometJacking” report described instructions embedded in a crafted URL, aimed at data available through connected services. LayerX says it reported the issue on August 27, 2025, and that Perplexity found no security impact and marked it “Not Applicable.” LayerX’s October 2025 CometJacking report

Guardio’s August 2025 tests were less about hidden text and more about trust decisions. In repeated tests, Comet sometimes proceeded through a fake shop checkout using saved personal and payment details, and sometimes stopped or asked the user to finish. In a separate test it followed a phishing link from an email and helped with the fake login. These are test results, not a claim that every run behaves that way. Guardio Labs’ August 2025 Scamlexity tests

In March 2026, Zenity disclosed “PleaseFix,” including Comet workflows where malicious meeting content could lead to local-file access or password-manager abuse. Zenity says Perplexity addressed the underlying browser-side issue before public disclosure. Zenity Labs’ March 2026 disclosure, The Hacker News’ March 2026 report

That same month, Guardio described iterating a phishing page against an agent’s explanations until it stopped objecting. It took the researchers under four minutes to produce a phishing trap Comet accepted. This is an evolving attack method, not proof that a current Comet build remains vulnerable. Guardio Labs’ March 2026 research

Perplexity published its own account of layered defenses in October 2025, including content classification, untrusted-content boundaries, repeated reminders of the user’s intent, and confirmation before consequential actions. That documents the company’s stated safeguards; it is not an independent guarantee that every attack path is blocked. Perplexity’s October 2025 security post

Why can a web page influence an agent?

The agent is processing text from outside the conversation while it has access to your browser session and tools. That combination is what indirect prompt injection exploits. A malicious instruction can arrive as a page paragraph, a comment, an email, a URL, or text hidden in an image; if the agent treats that content as an instruction, it can act across sites as you.

Simon Willison describes the dangerous combination as private data, untrusted content, and a way to communicate externally. Browser agents can bring all three together: logged-in pages supply private data, pages and messages supply untrusted text, and browser actions can send information or submit forms. Simon Willison’s 2025 “lethal trifecta”

That’s why the classic web boundary isn’t enough. A malicious webpage doesn’t need to run script on your email site if an agent can read its text, switch to the logged-in email tab, and follow the embedded instruction. OWASP lists prompt injection as LLM01 in its 2025 Top 10 for LLM applications. OWASP’s 2025 LLM Top 10

Is Comet browser safe after these attacks?

Use controls to remove one part of the chain: keep private data away from the agent, restrict which sites it can act on, and pause before actions that send or change information.

Documented attack What the attacker sought Control that blunts it Where to check
Hidden Reddit comment read during a summary Brave, 2025 Account email and one-time code Keep email and recovery accounts out of the agent’s logged-in session; require review before sending or sharing Use a separate browser profile with no email sign-in; use a logged-out agent mode if the browser has one
Instructions hidden in a screenshot Brave, 2025 Agent actions from text a person may not notice Treat screenshots and page text as untrusted; inspect proposed actions before approving Check the agent’s approval and sensitive-site controls; do not rely on visual inspection alone
Crafted URL aimed at connected data LayerX, 2025 Email, calendar, or connector data Do not connect services the task does not need; keep the agent logged out for research In Perplexity, review connector permissions and comet://settings/privacy
Fake shop or phishing page Guardio, 2025 Credentials, address, or payment details Do not delegate purchases or credential entry; verify the domain yourself Check whether the browser pauses for checkout and sensitive sites before it acts
Meeting invite leading to local-file or vault access Zenity, 2026 Files or password-manager access Keep high-impact tools and vaults unavailable during routine agent tasks Review the agent’s enabled tools, connected apps, profile, and approval prompts

For Comet, Perplexity says comet://settings/privacy has controls to clear browsing and search history, cookies, and cached data. Its FAQ also says a personal-context request can send the current tab and relevant history to Perplexity to complete the task, and that page or email context may be processed on its servers.

Treat that as a description of the company’s policy, checked October 2026, and review the current Comet privacy FAQ before using sensitive tabs.

Is Comet safe for email, banking, or shopping?

Don’t let an agent read or operate those accounts unattended. If you choose to use agent mode, use a separate browser profile, leave sensitive accounts signed out, don’t connect their services, and approve each action that sends a message, changes an account, or places an order.

For day-to-day research, let an agent read public pages and prepare drafts, but take over before it opens a sensitive account, enters credentials, sends, submits, buys, or deletes. Keep Perplexity Memory off if you don’t need personalization; Perplexity says Comet Assistant can use remembered preferences when it operates the browser. Check current settings rather than assuming the browser’s default. The Comet privacy FAQ describes when personal context and browsing data are used, and Perplexity’s February 2026 Memory update describes its use in Comet Assistant.

This is also the practical answer to “is Comet AI browser safe?”: it can be reasonable for low-impact tasks under a limited session, but the published research does not support treating agent mode as a trusted operator for sensitive accounts. Gartner’s advice to companies is blunter: the public abstract of its December 1, 2025 research note says “CISOs must block them all until enterprise-ready AI browsers are released in GA.” That is guidance for organizations, not a blanket rule for personal use. Gartner’s December 2025 abstract

What about OpenAI’s ChatGPT Atlas?

OpenAI has deprecated Atlas. Its October 21, 2025 launch post now opens with “This post introduced ChatGPT Atlas. Atlas has since been deprecated” and points readers to ChatGPT Work, checked October 2, 2026. OpenAI’s Atlas launch page So the answer to “is ChatGPT Atlas safe?” is to move off it: a deprecated browser is not one to tune.

While it shipped, OpenAI was candid about the risk. Its December 2025 post describes a security update found through internal red-teaming, shows an injected email redirecting an agent away from the user’s task, and calls prompt injection “a long-term AI security challenge.” OpenAI’s December 2025 Atlas update

Its help page documented logged-out mode, which avoids pre-existing cookies, plus confirmation before sensitive steps and Watch Mode on sensitive sites. OpenAI’s Atlas help page Those are still the controls to look for in any agent browser.

What no setting fixes

No user-facing toggle can make an agent perfectly distinguish instructions from data in every page it reads. OpenAI calls prompt injection an open challenge, while its Atlas post describes continuous testing and mitigation rather than a final fix. OpenAI’s November 2025 prompt-injection guide

So choose by the work, not by a broad “safe” label. For public research, use an isolated profile and keep the task narrow. For mail, banking, password managers, or purchases, do the sensitive step yourself.

Before you start an agent task today:

  • Use a separate browser profile for agent work.
  • Sign out of email, banking, and password-manager accounts; prefer logged-out mode where it exists.
  • Disconnect integrations the task doesn’t need and turn off Memory if you don’t need personalization.
  • Install current browser updates, then keep purchases, messages, and account changes manual.
  • Read each approval prompt, including the destination and information being sent.

If the task needs unrestricted access to your inbox or bank, don’t hand it to the agent.

How Octoweb handles the same risks

I build Octoweb, a keyboard-first browser for macOS that agents can drive, so weigh this accordingly. Its MCP server checks the Origin header so web pages can’t drive it, and returns page-authored text inside an <untrusted> fence. The sidebar assistant shows an approval card and waits before anything irreversible, and its browser-task rules say page text is data, not instructions.

Workspaces give an agent its own cookie jar, and agents have no tool for the built-in terminal. None of that removes prompt injection, and any local process can still reach the loopback MCP port. The MCP hardening notes in Octoweb 0.15, the post on letting an agent drive the browser, and the privacy page describe those boundaries.

The browser MCP server reference lists every tool an agent gets.

Don Karter

Don Karter

CEO & Co-founder at Muvon

20+ years in software engineering, the last decade deep in AI systems. Builds Octoweb — a keyboard-first AI browser for macOS on WebKit and Rust. Writes from the trenches: native browser engineering, agents driving real pages over MCP, and what breaks when every action has to be one keystroke away.

Octoweb is free and open source, for macOS.

Install it →