
These days, AI browsers are quite popular as all the AI companies are racing to launch an AI-powered browser. But some security researchers have uncovered new vulnerabilities in AI-powered browsers that allow hidden instructions, known as prompt injections, to manipulate users’ browsers without their knowledge. The findings, shared by Brave, highlight risks in Comet, Fellou, and potentially other agentic browsers.
The research, conducted by Artem Chaikin (Senior Mobile Security Engineer) and Shivan Kaul Sahib (VP, Privacy and Security), builds on prior discoveries involving Perplexity’s Comet browser. Unlike traditional browsers, agentic AI browsers can act on a user’s behalf, making even simple commands potentially dangerous if malicious instructions are injected.