To the surprise of no one in the security industry, processing untrusted, unvalidated input is a bad idea. Until about a week ago, Perplexity's AI-based Comet browser did just that - asked to summarize a web page, the AI-powered browser would ingest the text on the page, no questions asked, and process it. And if the page text - visible or hidden - happened to include malicious instructions, Comet would attempt to comply, carrying out what's known as an indirect prompt injection attack.
In July 2025, Perplexity launched Comet, a groundbreaking AI-powered web browser designed from the ground up for this era of intelligent automation. Comet integrates intelligence at its core, transforming browsing sessions into seamless, conversational workflows.