Brave discloses prompt injection in Comet
Brave shows hidden text on a web page can make Comet's assistant leak credentials and Gmail OTP codes from logged-in sessions.
Defined the core agentic-browser risk. The model cannot tell page content from user instructions, so same-origin protections do not apply. Perplexity patched in July/August, and Brave re-reported incomplete fixes. LayerX later showed 'CometJacking'.
- Date
- Wednesday, 20 August 2025
- Lab
- Brave / Perplexity
- Kind
- product
- Access
- app only
Researcher Artem Chaikin of Brave; Brave reported the issue 2025-07-27 and published 2025-08-20.
Sources
This record was checked against its sources on 6 October 2026. How we check