A study looking into agentic AI browsers has found that these emerging tools are vulnerable to both new and old schemes that could make them interact with malicious pages and prompts. Agentic AI browsers can autonomously browse, shop, and manage various online tasks (like handling email, booking tickets, filing forms, or controlling accounts). Perplexity’s Comet is currently the primary example of agentic AI browsers. Microsoft Edge is also embedding agentic browsing features through a Copilot integration, and OpenAI is currently developing its own platform codenamed ‘Aura’. Although these tools are currently aimed at tech enthusiasts and early adopters, Comet is quickly penetrating the mainstream consumer market. According to an examination focused primarily on Comet, these tools were released with inadequate security safeguards against known and novel attacks specifically crafted to target them. Tests from Guardio, a developer of browser extensions that protect against online threats (identity theft, phishing, malware), revealed that agentic AI browsers are vulnerable to phishing, prompt injection, and purchasing from fake shops. In one test, Guardio asked Comet to buy an Apple watch while on a fake Walmart site the researchers created using the Lovable service. Although in the experiment Comet was directed to the fake shop, in a real-life scenario an AI agent can end up in the same situation through SEO poisoning and malvertising. The model scanned the site without confir...
Perplexity’s Comet AI browser tricked into buying fake items online
BleepingComputer
·Bill Toulas
·Published Aug 20, 2025
·Updated
Affected Software
3 affected components
Perplexity Comet
Microsoft Edge
OpenAI Aura
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses vulnerabilities found in Perplexity’s Comet AI browser that resulted in it being tricked into purchasing fake items online.
2
What security implications are discussed?
The article highlights the risk that agentic AI browsers can be manipulated by malicious schemes, posing a threat to user security.
3
What products or software are affected?
The vulnerable products include Perplexity Comet, Microsoft Edge, and OpenAI Aura.
4
What type of attack did the Comet AI browser experience?
The Comet AI browser was tricked into interacting with malicious pages that led to purchasing fake items.
5
What does the research suggest about agentic AI browsers?
The research suggests that agentic AI browsers are susceptible to both old and new exploitation tactics.