Comet and Atlas can leak data, hijack accounts
Hidden webpage instructions can redirect AI actions in Perplexity Comet and ChatGPT Atlas. This can expose data or let an attacker take over accounts.
- Report priority
- Medium
- Targets
- Perplexity Comet+1 more
How it works
- An attacker hides instructions inside content on a webpage.
- The AI assistant reads that content while navigating or interacting with the site.
- In Comet demonstrations, nearly invisible image text and concealed Reddit comments passed existing safeguards.
- The hidden directions can redirect the assistant's actions, leading to exposed data or account takeover.
What to do
Check whether you use Comet or Atlas to navigate and interact with websites. A matching product indicates possible exposure, not proof of compromise. The retrieved evidence provides no affected version cutoff or reliable compromise check.
The retrieved evidence names no fixed Comet release, so ask Perplexity or your IT team to confirm whether your installed version addresses these findings. Atlas users should review OpenAI's Atlas notice, which marks the browser as deprecated and points readers toward current workflows.
Technical details
The research demonstrated indirect prompt injection against Comet and Atlas. This means instructions planted in website content can be treated as directions for the AI assistant. The supported Comet demonstrations used nearly invisible image text and a concealed Reddit comment. These were researcher demonstrations, not reports of malicious attacks against known victims.
The reported potential outcomes were data exfiltration and account takeover.