OpenAI's Atlas and Perplexity's Comet browsers are vulnerable to attacks that spoof the built-in AI sidebar and can lead users into following malicious instructions. The AI Sidebar Spoofing attack was devised by researchers at browser security company SquareX and works on the latest versions of the two browsers. The researchers created three realistic attack scenarios where a threat actor could use AI Sidebar Spoofing to steal cryptocurrency, access a target's Gmail and Google Drive services, and hijack a device. Atlas and Comet are agentic AI browsers that integrate large language models (LLMs) into a sidebar for users to interact with while browsing: ask to summarize the current page, execute commands, or perform automated tasks. Comet was released in July, while ChatGPT Atlas became available for macOS earlier this week. Since its release, Comet has been the target of multiple research [1, 2, 3] showing that it comes with security risks under certain circumstances. SquareX found that in both Comet and Atlas, it is possible to draw a fake sidebar over the genuine one using a malicious extension that injects JavaScript into the web page the user sees. The fake sidebar would be identical to the one in the agentic browser, creating a deceptive element that appears to be part of the standard user interface. Since the counterfeit overlays the real one and intercepts all interactions, users would be completely unaware of the fraud. "Once the victim opens a new browser tab, the e...
Spoofed AI sidebars can trick Atlas, Comet users into dangerous actions
BleepingComputer
·Bill Toulas
·Published Oct 23, 2025
·Updated
Affected Software
2 affected components
OpenAI Atlas
Perplexity Comet
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses vulnerabilities in OpenAI's Atlas and Perplexity's Comet browsers that allow spoofed AI sidebars to mislead users.
2
What security implications are discussed?
The article highlights potential risks where users could be tricked into taking dangerous actions by following malicious instructions from spoofed AI sidebars.
3
What products are affected by this vulnerability?
The affected products mentioned in the article are OpenAI Atlas and Perplexity Comet.
4
Who conducted the research on the AI sidebar spoofing attack?
The AI sidebar spoofing attack was devised by a team of researchers.
5
How does the spoofing attack impact user safety?
The spoofing attack poses a significant threat to user safety by potentially guiding them into harmful activities.