Perplexity’s Comet is a free Chromium-based browser on Windows, but the “August 2026 launch” framing attached to it is wrong: Comet’s desktop paywall was removed on October 2, 2025, Android arrived in November 2025, and the iPhone version followed on March 18, 2026. The useful news for Windows users is therefore not a new release, but what the browser has become after a year of shipping: a Chrome-compatible browser whose built-in Comet Assistant can read selected browser context and, with approval, take actions on websites.
That distinction is more than editorial housekeeping. A guide that presents the product as a fresh, free worldwide launch can lead readers to mistake old launch-period claims for current capabilities, pricing, or safeguards. Perplexity’s own changelog confirms the October 2025 free release, while reporting from Search Engine Journal and TechRepublic independently documented the shift from the original $200-per-month Perplexity Max gate to a free desktop download.
Comet is worth testing if its side-panel assistant can replace the repeated cycle of copying text between tabs and an AI chat window. It is not a browser to hand unrestricted access to email, calendars, corporate SaaS, password managers, or payment flows simply because it can perform a task after being asked.
On Windows, Comet behaves like a familiar Chromium browser. Perplexity’s current setup documentation confirms that users can import bookmarks, history, and passwords from another browser, set Comet as the default handler for web links, and install most Chrome extensions. That substantially lowers the cost of trying it for anyone already standardised on Chrome or Edge extensions.
The important change is the assistant panel. Instead of merely answering a query in a search tab, Comet Assistant can work with a current page, selected text, a specifically referenced tab, or a broader set of open tabs when the user invokes those capabilities. Perplexity positions it for summarizing articles and PDFs, comparing products, preparing research, drafting email replies, scheduling meetings, and navigating multi-step web tasks.
That can be genuinely helpful for low-risk work. A user comparing vendor documentation in five tabs can ask for differences in supported Windows builds, licensing conditions, or deployment prerequisites without manually collating each page. A user reading a long support thread can request a concise chronology of the issue and proposed fixes. Those uses retain a human at the keyboard and treat Comet as a reading and synthesis tool.
The risk increases when “summarize this” turns into “go do this.” An agentic browser has access to the same open web pages, logged-in sessions, and potentially sensitive content that the user sees. The assistant’s advantage—context from pages and tabs—is also the reason it deserves stricter controls than a standalone chatbot.
“Free” also needs a practical reading. It means the browser can be downloaded and used without the former Max-only admission price. It does not mean every search model, every research feature, or every long-running autonomous workflow is unlimited for every user. Perplexity continues to sell Pro, Max, and enterprise services, and its product pages reserve higher-capacity and specialist capabilities for paid plans.
The original guide’s numerical limits and feature table should not be treated as a stable contract. Perplexity changes plan terms and model availability regularly, and the public material reviewed for this report does not substantiate every asserted entitlement—such as a fixed number of daily Pro searches, universal GPT Realtime 1.5 voice access, or PayPal-based purchasing for all users. Anyone evaluating Comet for work should confirm the capabilities shown inside their own account rather than base a procurement decision on a third-party plan summary.
There is also a platform caveat. Comet is now available on Windows, macOS, Android, and iOS, but parity is not guaranteed. MacRumors reported when the iPhone version launched in March that it lacked extensions, for example. Windows users should not assume a feature demonstrated on an Android phone or iPhone will expose the same controls, extension support, or background behavior on the desktop.
That is not equivalent to saying that nothing sensitive can leave the device. Perplexity says it may process current-page context, including page text and email content, on its servers when that information is needed to fulfill an Assistant request. Its Comet Assistant privacy documentation says that page content, history items, and open-tab context used for an AI request may be retained for up to 30 days to support Library and query-history functions.
The practical boundary is simple: the password itself may remain local, but an assistant asked to summarize an invoice, organize email, research a customer, or complete an order must receive enough visible content and browsing context to perform that task. Sensitive data can be exposed through the content of the page, even when a credential vault is working exactly as designed.
Perplexity says users can disable the assistant or block it on particular sites. Its enterprise controls go further, allowing administrators to designate domains as browser-control, read-only, or no-access zones. That is a meaningful control model, particularly for managed Windows deployments, but it also underscores the deployment reality: an AI assistant should have a defined scope, not ambient access to every authenticated session in the browser.
For an individual Windows PC, start by blocking Assistant access to banking, payroll, medical, HR, identity-provider, and administrative-console domains. For business deployment, mirror that principle through policy before offering the browser to staff. Perplexity’s enterprise documentation says Comet supports Windows and macOS deployment through existing MDM infrastructure and has more than 500 Chromium-derived policies; that makes controls feasible, but it does not make an unmanaged rollout safe by default.
This is not a theoretical limitation that only affects Perplexity. But Comet has already been a live example of how the problem can affect browser agents. Brave researchers reported in August 2025 that a malicious instruction in webpage content could be included when Comet was asked to summarize that page, potentially steering the assistant toward cross-site actions. Guardio also tested Comet against common scam patterns; as reported by Windows Central, some tests led the agent toward a fake shopping site and phishing workflow, although behavior varied and the assistant sometimes stopped or required confirmation.
A separate LayerX finding, dubbed CometJacking, involved a malicious prompt embedded in a URL. Time reported that the proof of concept could cause the assistant to extract information from connected Gmail and calendar services in a controlled demonstration. Perplexity told Time that it had independently identified and patched the issue, said it had not been exploited, and criticized the earlier bug report as unclear.
The conclusion is not that every Comet task will leak data or that the browser is uniquely insecure. It is that browser agents create a path from hostile web content to action in authenticated services, and the industry has not solved the problem. Perplexity itself acknowledges the attack class: its BrowseSafe research describes indirect prompt injection as a new attack surface for browser-based agents and presents its own mitigation work as defense in depth, not perfection.
A confirmation dialog is useful, but it cannot repair every bad decision made before the moment of confirmation. If an agent has selected a fraudulent retailer, opened an adversarial document, or drafted an email containing sensitive details, the user needs enough visibility to recognize the bad premise. That is why approvals must be treated as a last checkpoint, not proof that the preceding reasoning was trustworthy.
Avoid delegating the following until browser-agent defenses mature and your organization has established controls:
Comet’s free price removes the old $200 barrier, and its Chromium base makes it easier to trial than a wholly new browser. But the critical change is not that an AI sidebar can summarize tabs. It is that the sidebar can act inside the same authenticated browser session as the user. For Windows users, that makes Comet a promising research browser and a deliberately constrained automation tool—not a replacement for judgment at the keyboard.
Comet is worth testing if its side-panel assistant can replace the repeated cycle of copying text between tabs and an AI chat window. It is not a browser to hand unrestricted access to email, calendars, corporate SaaS, password managers, or payment flows simply because it can perform a task after being asked.
Comet is a browser first, with an agent attached
On Windows, Comet behaves like a familiar Chromium browser. Perplexity’s current setup documentation confirms that users can import bookmarks, history, and passwords from another browser, set Comet as the default handler for web links, and install most Chrome extensions. That substantially lowers the cost of trying it for anyone already standardised on Chrome or Edge extensions.The important change is the assistant panel. Instead of merely answering a query in a search tab, Comet Assistant can work with a current page, selected text, a specifically referenced tab, or a broader set of open tabs when the user invokes those capabilities. Perplexity positions it for summarizing articles and PDFs, comparing products, preparing research, drafting email replies, scheduling meetings, and navigating multi-step web tasks.
That can be genuinely helpful for low-risk work. A user comparing vendor documentation in five tabs can ask for differences in supported Windows builds, licensing conditions, or deployment prerequisites without manually collating each page. A user reading a long support thread can request a concise chronology of the issue and proposed fixes. Those uses retain a human at the keyboard and treat Comet as a reading and synthesis tool.
The risk increases when “summarize this” turns into “go do this.” An agentic browser has access to the same open web pages, logged-in sessions, and potentially sensitive content that the user sees. The assistant’s advantage—context from pages and tabs—is also the reason it deserves stricter controls than a standalone chatbot.
The free browser is not the same thing as unlimited AI access
The submitted account accurately recalls that Comet began as a perk for Perplexity Max, the company’s $200 monthly tier. But it incorrectly moves the public release to July 29, 2026. Perplexity said on October 3, 2025 that Comet was available for everyone worldwide at no cost, following the company’s October 2 announcement.“Free” also needs a practical reading. It means the browser can be downloaded and used without the former Max-only admission price. It does not mean every search model, every research feature, or every long-running autonomous workflow is unlimited for every user. Perplexity continues to sell Pro, Max, and enterprise services, and its product pages reserve higher-capacity and specialist capabilities for paid plans.
The original guide’s numerical limits and feature table should not be treated as a stable contract. Perplexity changes plan terms and model availability regularly, and the public material reviewed for this report does not substantiate every asserted entitlement—such as a fixed number of daily Pro searches, universal GPT Realtime 1.5 voice access, or PayPal-based purchasing for all users. Anyone evaluating Comet for work should confirm the capabilities shown inside their own account rather than base a procurement decision on a third-party plan summary.
There is also a platform caveat. Comet is now available on Windows, macOS, Android, and iOS, but parity is not guaranteed. MacRumors reported when the iPhone version launched in March that it lacked extensions, for example. Windows users should not assume a feature demonstrated on an Android phone or iPhone will expose the same controls, extension support, or background behavior on the desktop.
Passwords stay local, but requested page context does not
One claim in the supplied material is broadly supported but needs sharper boundaries: Comet does not send stored passwords or credit-card details to Perplexity’s servers as a normal part of browser operation. Perplexity’s privacy and security FAQ says credentials such as passwords and payment cards remain in the device’s secure operating-system vault, while the company’s Windows and macOS setup guidance describes local encrypted storage for password management and autofill.That is not equivalent to saying that nothing sensitive can leave the device. Perplexity says it may process current-page context, including page text and email content, on its servers when that information is needed to fulfill an Assistant request. Its Comet Assistant privacy documentation says that page content, history items, and open-tab context used for an AI request may be retained for up to 30 days to support Library and query-history functions.
The practical boundary is simple: the password itself may remain local, but an assistant asked to summarize an invoice, organize email, research a customer, or complete an order must receive enough visible content and browsing context to perform that task. Sensitive data can be exposed through the content of the page, even when a credential vault is working exactly as designed.
Perplexity says users can disable the assistant or block it on particular sites. Its enterprise controls go further, allowing administrators to designate domains as browser-control, read-only, or no-access zones. That is a meaningful control model, particularly for managed Windows deployments, but it also underscores the deployment reality: an AI assistant should have a defined scope, not ambient access to every authenticated session in the browser.
For an individual Windows PC, start by blocking Assistant access to banking, payroll, medical, HR, identity-provider, and administrative-console domains. For business deployment, mirror that principle through policy before offering the browser to staff. Perplexity’s enterprise documentation says Comet supports Windows and macOS deployment through existing MDM infrastructure and has more than 500 Chromium-derived policies; that makes controls feasible, but it does not make an unmanaged rollout safe by default.
Prompt injection remains the central security problem
The most important omitted context in upbeat Comet guides is that autonomous browsing changes the threat model. Prompt injection is the attack in which hostile instructions embedded in a webpage, document, comment, image description, or URL are treated by the model as instructions rather than untrusted content.This is not a theoretical limitation that only affects Perplexity. But Comet has already been a live example of how the problem can affect browser agents. Brave researchers reported in August 2025 that a malicious instruction in webpage content could be included when Comet was asked to summarize that page, potentially steering the assistant toward cross-site actions. Guardio also tested Comet against common scam patterns; as reported by Windows Central, some tests led the agent toward a fake shopping site and phishing workflow, although behavior varied and the assistant sometimes stopped or required confirmation.
A separate LayerX finding, dubbed CometJacking, involved a malicious prompt embedded in a URL. Time reported that the proof of concept could cause the assistant to extract information from connected Gmail and calendar services in a controlled demonstration. Perplexity told Time that it had independently identified and patched the issue, said it had not been exploited, and criticized the earlier bug report as unclear.
The conclusion is not that every Comet task will leak data or that the browser is uniquely insecure. It is that browser agents create a path from hostile web content to action in authenticated services, and the industry has not solved the problem. Perplexity itself acknowledges the attack class: its BrowseSafe research describes indirect prompt injection as a new attack surface for browser-based agents and presents its own mitigation work as defense in depth, not perfection.
A confirmation dialog is useful, but it cannot repair every bad decision made before the moment of confirmation. If an agent has selected a fraudulent retailer, opened an adversarial document, or drafted an email containing sensitive details, the user needs enough visibility to recognize the bad premise. That is why approvals must be treated as a last checkpoint, not proof that the preceding reasoning was trustworthy.
A sensible Windows deployment starts with read-only work
Comet’s best current role is research assistance: reading a page, comparing explicitly selected tabs, finding information within a user’s own browsing session, and producing a draft that the user reviews. Those are high-frequency tasks where the assistant can save clicks without being granted authority over money, credentials, or external communications.Avoid delegating the following until browser-agent defenses mature and your organization has established controls:
- Do not let Comet complete purchases, renewals, banking work, tax submissions, or payroll changes.
- Do not give it broad access to privileged Microsoft 365, Entra ID, Azure, Intune, VPN, EDR, or help-desk administration sessions.
- Do not use it to open links and autonomously act on messages from unknown senders.
- Do not permit it to send email, alter calendars, or upload files without reviewing the destination, attachments, and final text.
- Do not import a full personal or work profile into a trial installation if a clean test profile will answer the evaluation question.
Comet’s free price removes the old $200 barrier, and its Chromium base makes it easier to trial than a wholly new browser. But the critical change is not that an AI sidebar can summarize tabs. It is that the sidebar can act inside the same authenticated browser session as the user. For Windows users, that makes Comet a promising research browser and a deliberately constrained automation tool—not a replacement for judgment at the keyboard.
References
- Primary source: secnews.gr
Published: 2026-08-02T17:42:40+00:00
Loading…
www.secnews.gr - Related coverage: perplexity.ai
Loading…
www.perplexity.ai - Related coverage: macrumors.com
Loading…
www.macrumors.com - Related coverage: searchenginejournal.com
Loading…
www.searchenginejournal.com - Related coverage: techrepublic.com
Loading…
www.techrepublic.com - Related coverage: perplexity.ai
Loading…
www.perplexity.ai - Related coverage: hub-prod.perplexity.ai
Loading…
hub-prod.perplexity.ai - Related coverage: play.google.com
Loading…
play.google.com - Related coverage: explore.gcts.edu
Loading…
explore.gcts.edu - Related coverage: assets.ctfassets.net
Loading…
assets.ctfassets.net - Related coverage: s3.documentcloud.org
Loading…
s3.documentcloud.org - Related coverage: techradar.com
Loading…
www.techradar.com - Related coverage: tomsguide.com
Loading…
www.tomsguide.com - Related coverage: time.com
What to Know About the Security Flaw in Perplexity’s Comet
Perplexity's Comet browser could until recently be hijacked by malicious links, causing it to siphon personal information and send it to mock attackers.time.com - Related coverage: cincodias.elpais.com
Loading…
cincodias.elpais.com - Related coverage: windowscentral.com
Loading…
www.windowscentral.com - Related coverage: research.perplexity.ai
Loading…
research.perplexity.ai - Related coverage: homes.cs.washington.edu
Loading…
homes.cs.washington.edu - Related coverage: techradar.com
Loading…
www.techradar.com - Related coverage: windowscentral.com
Loading…
www.windowscentral.com - Related coverage: time.com
5 Things to Know Before Using an AI Browser
A new crop of AI browsers, notably OpenAI’s ChatGPT Atlas and Perplexity’s Comet, is available to users. But privacy concerns abound.time.com - Related coverage: androidcentral.com
Loading…
www.androidcentral.com - Related coverage: androidauthority.com
Loading…
www.androidauthority.com - Related coverage: hamady.org
Loading…
www.hamady.org