The security vulnerability we found in Perplexity’s Comet browser this summer is not an isolated issue. Indirect prompt injections are a systemic problem facing Comet and other AI-powered browsers. Today we’re publishing details on more security vulnerabilities we uncovered.
Indirect prompt injection attacks occur when malicious instructions are hidden in web content like webpages. When an LLM analyzes the content, it obeys the hidden instructions because it believes they’re real commands from the user.
In this thread, we summarize the new types of prompt injection attacks we uncovered. You can read more details on them in today’s blog: https://brave.com/blog/unseeab...
Perplexity Comet’s AI assistant can take screenshots of websites and analyze them for users. However, Comet will also follow instructions hidden on a webpage that it screenshots.
Fellou browser has some resistance to hidden instruction attacks. However, it still treats all visible content on websites as trusted. Simply asking the browser to visit a site with instructions will cause the LLM to process and obey those instructions.
The scariest aspect of these security flaws is that an AI assistant can act with the user’s authenticated privileges. An agentic browser hijacked by a malicious site can access a user’s banking, work email or other sensitive accounts.
To make agentic browsing less risky, developers should: - Isolate agentic browsing from regular browsing - Require explicit consent from users for agentic browsing actions like opening sites or reading emails However, larger structural changes are needed in the long term.
We disclosed these security vulnerabilities to the companies involved before publicly revealing them today. Openly discussing the security challenges of agentic AI results in a safer Web for everyone.
@brave So... do a better job than Perplexity does. Otherwise, it looks like you're trying to justify your inaction. P.S. I love Brave and have been using it for years ;)
@antonp_me Offering more secure agentic browsing is the plan 🙂 But we want users of other browsers to be safer too so that's why finding and disclosing these bugs is important.
@brave so I should use brave now? 😅 fk no
@locomunkey Regardless of what browser you use, we just want you to be aware of the risks that come with agentic browsing.
@brave Today ChatGPT is releasing a browser will you be testing that too?
@Pavaaannnn I'm sure we'll be trying it out
@ThrashyArt Hi, the team looking into this!
@brave Brave user here. Will use no other 🔥
@brave Appreciate the transparency here. Wild that a faint line of text in an image can trick an AI into leaking data. The future of web security is starting to look like optical illusions for machines. Curious how Brave plans to bring its security-first approach into the era of agentic
@brave we can all practice safe browsing by avoiding the use of agentic mode in all of our ai-browsers. it's not an always on thing.
@brave Have you looked at BrowserOS at all? Seems like it has more extensive agentic tools built in and only a loose association of Github contributors developing.
@brave This is true for AI tools as well I got to know this through an article and made a small explanation - demo video on this as well. 🔗 : https://youtu.be/bRxTMPrHYXc?s...
@brave In short, if you’re using an AI browser you’re basically exposing everything to that company as they can see web pages content and remember’s what was seen.
@brave AI browsers are powerful — but every new capability opens another attack surface. Security needs to scale as fast as innovation. 🔒
@brave also for agentic workflows they have to send you context back - so anything on the website is part of that context - if you're logged into a bank website or any personal page - that becomes part of the context - and since chats are not encrypted e2e - everythings visible server
@brave the new browser war is gettin' NASTY
@brave Its a sign to switch to brave browser 🤭
@brave Thanks as always Brave
@brave Can u check Chatgpt Atlas next?
@brave You guys are doing great job
@brave holy shit
@brave @hillofdirt Is this applicable to Atlas also?
@brave Would be cool to see your take on OpenAI's new browser.
@brave 👀
@brave Breaches are everywhere. “How is this still a consideration?” Are we waiting for whales to breach the beach? Makes no sense idle feet in flippers
