You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cometjacking
About this tag
Cometjacking is a prompt injection attack targeting AI-powered browsers and agentic assistants. These next-generation browsers, such as Perplexity's Comet and Microsoft's Copilot, can read and act on web content on behalf of users. Cometjacking exploits this by hiding malicious instructions within otherwise normal web pages, tricking the AI assistant into performing actions that compromise account security, leak private data, or execute unauthorized commands. This attack vector represents a growing threat to the trust model of AI browsers, as it weaponizes the very features designed to help users. Discussions on WindowsForum cover the mechanics of cometjacking, its implications for enterprise IT and personal security, and potential mitigations like stricter content validation and user permission controls.
AI browsers — the new generation of agentic assistants that read, reason, and act on web pages for you — are now being weaponized by a fresh class of attacks that hide instructions inside otherwise normal web content, threatening account security, private data, and the very notion of what a...