
- Zenity researchers uncovered PleaseFix, a zero-click indirect prompt injection flaw in Comet browser
- Malicious calendar invites could trick the AI into exfiltrating passwords and sensitive files without user awareness
- Bug patched with restrictions on file:// access, preventing agents from reading local filesystem