Perplexity Comet AI Browser Exposes Users to Security Breach and Copyright Lawsuits

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Perplexity's AI-powered Comet browser was found to have a major security flaw, allowing attackers to steal users' sensitive data and account credentials via hidden malicious instructions. Additionally, Perplexity faces lawsuits from Japanese media for unauthorized copying and storage of copyrighted content by its AI system.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event explicitly involves an AI system (Perplexity AI) that uses AI to search and summarize news content. The unauthorized use of copyrighted material and dissemination of inaccurate summaries have directly led to harm in terms of intellectual property rights violations and commercial damage to the news companies. Therefore, this qualifies as an AI Incident under the framework, as the AI system's use has directly led to violations of intellectual property rights and harm to commercial interests.[AI generated]
AI principles
Privacy & data governanceRobustness & digital securityAccountabilitySafetyRespect of human rights

Industries
Consumer servicesDigital securityMedia, social platforms, and marketing

Affected stakeholders
ConsumersBusiness

Harm types
Human or fundamental rightsEconomic/PropertyReputational

Severity
AI incident

Business function:
Other

AI system task:
Interaction support/chatbotsContent generation


Articles about this incident or hazard

Thumbnail Image

Perplexity 推 Comet Plus 訂閱服務:用家月費 US$5,出版商將獲 8 成分潤

2025-08-26
Yahoo News
Why's our monitor labelling this an incident or hazard?
The article describes a new subscription service related to an AI system (Perplexity's Comet Agent) and its revenue-sharing model with publishers to mitigate copyright infringement issues. However, it does not report any realized harm, nor does it indicate a plausible future harm directly caused by the AI system. Instead, it is a development in the AI ecosystem addressing prior concerns, making it complementary information rather than an incident or hazard.
Thumbnail Image

Perplexity 推 Comet Plus 訂閱服務:用家月費 US$5,出版商將獲 8 成分潤

2025-08-26
Yahoo News (Taiwan)
Why's our monitor labelling this an incident or hazard?
The event involves the use of an AI system (Comet Agent) that interacts with media websites, and the new subscription service is designed to share revenue with publishers to mitigate copyright infringement issues. However, the article does not describe any realized harm or direct incident caused by the AI system; rather, it presents a business and governance response to prior copyright concerns. Therefore, this is best classified as Complementary Information, as it provides context and a response to existing AI-related copyright issues without reporting a new incident or hazard.
Thumbnail Image

日經朝日控Perplexity AI侵權 各求償22億日圓 - 國際 - 自由時報電子報

2025-08-26
Liberty Times Net
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Perplexity AI) that uses AI to search and summarize news content. The unauthorized use of copyrighted material and dissemination of inaccurate summaries have directly led to harm in terms of intellectual property rights violations and commercial damage to the news companies. Therefore, this qualifies as an AI Incident under the framework, as the AI system's use has directly led to violations of intellectual property rights and harm to commercial interests.
Thumbnail Image

AI新創推「共享收入模型」 當內容被引用 出版商就可分潤 | 聯合新聞網

2025-08-26
UDN
Why's our monitor labelling this an incident or hazard?
The event involves the use of an AI system (Perplexity's AI assistant/search engine) that uses publisher content to generate responses. The legal actions by publishers alleging copyright infringement constitute a violation of intellectual property rights, which is a recognized harm under the AI Incident definition. Since the AI system's use of content has directly led to legal disputes over rights violations, this qualifies as an AI Incident.
Thumbnail Image

日經朝日控Perplexity AI侵權 各求償22億日圓 | 國際焦點 | 國際 | 經濟日報

2025-08-26
Udnemoney聯合理財網
Why's our monitor labelling this an incident or hazard?
The event clearly involves an AI system (Perplexity AI) that uses AI to collect, summarize, and disseminate news content without authorization, leading to violations of copyright law and harm to the news organizations' business and reputation. This fits the definition of an AI Incident because the AI system's use has directly led to a breach of intellectual property rights and commercial harm. The legal action and claims for damages further confirm the materialization of harm linked to the AI system's use.
Thumbnail Image

日经和朝日起诉美国AI检索公司侵犯著作权

2025-08-27
Nikkei Chinese
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (generative AI search and summarization) whose use has directly led to harm: copyright infringement and commercial damage to news organizations. The unauthorized data scraping and summarization by the AI system violate copyright laws and cause reputational harm, fulfilling the criteria for an AI Incident under violations of intellectual property rights and harm to commercial interests. The involvement of the AI system in the development and use stages is clear, and the harm is realized and ongoing, not merely potential. Therefore, this is classified as an AI Incident.
Thumbnail Image

危,AI浏览器被曝大漏洞,用户邮箱验证码扒精光,盗号仅需150秒-36氪

2025-08-26
36氪:关注互联网创业
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (the AI browser Comet acting as an AI agent) whose malfunction or insecure design has directly led to realized harm: attackers can steal email verification codes and hijack user accounts. The harm includes violations of privacy and security, which fall under violations of human rights and harm to property. The article details how the AI system's design and operation enable this attack, and the harm is ongoing and demonstrated. Therefore, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

危!AI浏览器被曝大漏洞,用户邮箱验证码扒精光,盗号仅需150秒

2025-08-26
凤凰网(凤凰新媒体)
Why's our monitor labelling this an incident or hazard?
The article explicitly describes an AI system (the Comet AI browser agent) whose malfunction and design flaws allow attackers to exploit it by injecting malicious instructions in web content. This leads directly to the theft of sensitive user information (email verification codes) and unauthorized account access, causing harm to users' privacy and security. The harm is realized and ongoing, with the AI system playing a pivotal role in enabling the attack. The event meets the criteria for an AI Incident because the AI system's use and malfunction have directly led to significant harm to individuals' privacy and security.
Thumbnail Image

2025-08-26
英国金融时报中文版
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Perplexity) whose use of copyrighted content has led to legal action alleging violation of intellectual property rights, which is a breach of obligations under applicable law protecting intellectual property rights. Since the lawsuit is a direct consequence of the AI system's use of content, this constitutes an AI Incident under the framework.
Thumbnail Image

日經朝日控Perplexity AI侵權 各求償22億日圓 | 國際 | 中央社 CNA

2025-08-26
Central News Agency
Why's our monitor labelling this an incident or hazard?
The event clearly involves an AI system (Perplexity AI) that uses AI to search, collect, and summarize news content. The unauthorized use of copyrighted material and the generation of inaccurate summaries have directly led to violations of intellectual property rights and commercial harm to the news organizations. This fits the definition of an AI Incident because the AI system's use has directly led to harm (violation of rights and commercial damage). The legal action and claims for damages further confirm the materialization of harm rather than a potential risk. Therefore, this event is classified as an AI Incident.
Thumbnail Image

日經新聞、朝日新聞加入讀賣新聞提告 Perplexity 行列,三社賠償金共高達 13.5 億元

2025-08-26
TechNews 科技新報 | 市場和業內人士關心的趨勢、內幕與新聞
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Perplexity AI) that uses large language models to scrape and summarize news content without authorization, leading to legal claims of intellectual property rights violations by the affected newspapers. The harm is realized as the newspapers seek compensation for unauthorized use of their content, which is a breach of intellectual property rights. This fits the definition of an AI Incident because the AI system's use has directly led to a violation of rights and legal harm. The event is not merely a potential risk or a complementary update but a concrete legal action due to harm caused by the AI system's operation.
Thumbnail Image

向媒體界遞橄欖枝?Perplexity推出「訂閱分潤」模式,承諾80%收益回饋出版商

2025-08-26
數位時代
Why's our monitor labelling this an incident or hazard?
The article explicitly involves AI systems (Perplexity's AI search engine and AI agents) and their use in content scraping and summarization, which has led to legal disputes and accusations of intellectual property rights violations. However, the article does not report a new AI Incident causing direct or indirect harm such as injury, disruption, or confirmed rights violations beyond ongoing litigation. Instead, it focuses on Perplexity's new revenue-sharing model as a mitigation effort and the ongoing conflict with media and security companies. This fits the definition of Complementary Information, as it updates on responses and developments related to AI harms but does not describe a new primary harm event.
Thumbnail Image

21世纪经济报道记者肖潇 AI浏览器的安全隐患再被警示。 近日,AI搜索明星公司Perplexity的浏览器Comet被曝存在重要安全漏洞。攻击者无需懂代码,只需在论坛评论区留下恶意指令,就能诱导 AI 智能体泄露用户的邮箱、验证码等敏感信息。 Comet是Perplexity公司上个月发布的AI原生浏览器,目前面向付费用户开放。与传统浏览器不同,它几乎在所有浏览场景里嵌入了 AI:用户既能在搜索栏直接发问,也能在浏览网页时随时唤出 AI,让其读屏、填表、写邮件和预订机票。 这一漏洞最先由竞争对手 Brave 浏览器的美国安全团队发现。他们在测试过程中仅做了两步: 第一步,在 Reddit 论坛一篇帖子下,留下带"剧透标签"的恶意指令,让用户无法看到具体内容; 第二步,当 Comet 用户点击"总结当前网页"时,AI 智能体会读取这条隐藏指令并自动执行。 最终AI智能体拿到了用户的邮箱地址,拿到验证码和一次性密码(OTP),完成盗号。整个过程耗时2分30秒。 从演示视频中还可以看到,由于AI智能体的部分后台操作只有文字描述,没有界面展示,所以用户也并没有看到AI在登录自己的邮箱。 Brave安全团队暗示,他们早在7月25日就将这一安全漏洞报告给了Perplexity,但似乎没有得到重视。尽管Perplexity宣称进行了初步修复,但 Brave 随后两次验证发现问题仍未完全解决,而且Perplexity也没有分享修复方案。 Perplexity 质疑了这一说法。一位发言人告诉媒体,该安全漏洞"在任何人发现之前就已修复",并表示没有用户数据被泄露。"我们直接与 Brave 合作,识别并修复了这个问题。" 需要指出,Brave浏览器也提供了AI智能体Leo,但公司称,自身"网页总结功能"仅限于内容分析,无法指示 AI 执行独立操作。不过其也承认,所有AI智能体都在面临类似的挑战:传统网络安全体系已经不足,需要全新的安全与隐私架构。 "随着用户逐渐习惯AI浏览器,并开始将银行、医疗保健和其他重要网站的敏感数据授权给AI,风险就会成倍增加,如果AI出现幻觉,执行你未请求的操作该怎么办?更糟糕的是,如果是一个看似无害的网站,或者社交媒体里的评论,通过隐形指令的方式来窃取你的登录凭证,又该怎么办?"Brave在博客中写道。 在全球范围内,智能体已成为2025年的核心战场。除了海外激烈布局的苹果、Anthropic、谷歌、OpenAI,国内的百度、字节、腾讯、阿里也已全面投入。 此前21记者报道过,"间接提示词攻击"是目前AI智能体的核心安全风险之一。攻击者可通过网页、PDF 或聊天消息注入隐藏指令,让大模型偏离用户原始请求。(详见:《智能体体检报告 -- -- 安全全景扫描》) "现在一些智能体的交互界面非常简洁,也没有复杂的数据输入接口,大家会误以为被攻击的可能性变小了。"一家互联网大厂安全团队的负责人对21记者谈到,但这反而让开发者掉以轻心,忽视了新型攻击的隐蔽性。 一个已发生的案例是,瑞士人工智能安全研究公司Invariant Labs在今年4月测试发现,可以劫持智能体窃取 WhatsApp 用户的聊天记录。尽管大部分智能体在执行敏感操作任务时需要用户手动确认,但攻击者可以把"恶意指令"隐藏在一段超长的滚动消息中,用户很难察觉。 而在这类攻击频频出现后,业界也在尝试不同的安全架构。 Brave 提出的思路是为 AI 浏览器建立"四道防线":第一,AI浏览器应该区分用户指令和网站内容,不能把网页内容也视为指令;第二,AI智能体要单独检查,执行任务是否符合用户原始要求;第三,安全和隐私敏感的操作都需要用户的明确确认;第四,AI代理模式与常规浏览模式需要隔离。 而另一类做法,则是从系统层面彻底换一种思路。谷歌、OpenAI、Anthropic 等公司目前都避免推出与Comet类似的功能,而是转向虚拟机、云上浏览器模式。国内的阿里巴巴的无影云,以及智谱最新的 AutoGLM"虚拟手机",也是类似的探索。

2025-08-26
证券之星
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (the AI-powered Comet browser) whose malfunction or exploitation directly caused harm to users by leaking sensitive information and enabling account theft. The attackers used hidden malicious instructions to manipulate the AI system into performing unauthorized actions, leading to a breach of user privacy and security. This fits the definition of an AI Incident because the AI system's use and malfunction directly led to harm to persons (data theft and account compromise). The article also discusses broader security challenges and responses, but the primary focus is on the realized harm from this specific vulnerability.
Thumbnail Image

AI浏览器被曝重大安全漏洞,2分30秒内完成盗号

2025-08-26
21jingji.com
Why's our monitor labelling this an incident or hazard?
The AI system (Comet's embedded AI agent) is explicitly involved as it processes user commands and webpage content, including malicious hidden instructions, which it executes automatically. This leads directly to harm (theft of sensitive information and account takeover), fulfilling the criteria for an AI Incident. The event involves the use and malfunction of the AI system, resulting in violations of user rights and harm to property (user accounts). The detailed description of realized harm and the AI system's pivotal role in causing it confirms classification as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

为应对"AI版权争议",Perplexity推出4250万美元分成计划

2025-08-25
k.sina.com.cn
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Perplexity AI) whose use has led to allegations of copyright infringement, a violation of intellectual property rights. This constitutes harm under the AI Incident definition (c). The company's revenue-sharing plan is a response to these realized harms and legal challenges, indicating that the copyright violation has occurred or is ongoing. Therefore, this qualifies as an AI Incident rather than a hazard or complementary information, as the harm is materialized and the AI system's use is central to the issue.
Thumbnail Image

危!AI浏览器被曝大漏洞,用户邮箱验证码扒精光,盗号仅需150秒

2025-08-26
k.sina.com.cn
Why's our monitor labelling this an incident or hazard?
The article explicitly describes an AI system (the Comet AI browser agent) that executes malicious instructions embedded in web content, leading to unauthorized access to users' email accounts and verification codes. This constitutes a direct harm to users' privacy and security, fulfilling the criteria for an AI Incident under the framework. The harm is realized, not just potential, as attackers can steal sensitive information and hijack accounts. The involvement of the AI system is central to the incident, as the AI agent's behavior enables the attack. Therefore, this event qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

AI浏览器被曝大漏洞 用户邮箱验证码扒精光 盗号仅需150秒 - cnBeta.COM 移动版

2025-08-26
cnBeta.COM
Why's our monitor labelling this an incident or hazard?
The article explicitly describes an AI system (Comet AI browser agent) whose use and design flaws have directly led to security breaches compromising user accounts and sensitive data. The AI system executes malicious instructions hidden in web content, leading to unauthorized access and theft of verification codes, which is a clear harm to users' privacy and security. The harm is realized, not just potential, and involves violations of fundamental rights to privacy and security. The involvement of the AI system in causing this harm is direct and central to the incident. Hence, this event meets the criteria for an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Perplexity Comet Plus|新模式與出版商分成 - EJ Tech

2025-08-27
EJ Tech
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Perplexity's AI search and summarization capabilities) used to access and present publisher content. The legal dispute alleges unauthorized copying and storage of content by the AI system, which constitutes a violation of intellectual property rights. Since the alleged unauthorized use has already occurred and legal claims for damages and content deletion are underway, this constitutes a violation of intellectual property rights caused by the AI system's use. Therefore, this qualifies as an AI Incident under the category of violations of intellectual property rights.
Thumbnail Image

日經、朝日新聞控告Perplexity侵害著作權 各索賠22億日元 | 鉅亨網 - 美股雷達

2025-08-27
Anue鉅亨
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Perplexity's AI search and summarization tool) that uses copyrighted content without permission, which constitutes a violation of intellectual property rights. This is a direct harm related to the AI system's development and use, as it infringes copyright laws and causes commercial damage to the news organizations. Therefore, this qualifies as an AI Incident under the framework because the AI system's use has directly led to a breach of intellectual property rights and commercial harm.