Depositphotos / Perplexity
The developers of the Brave browser have shown how hidden text on a page can be used to make Perplexity’s Comet AI a similar browser perform any actions.
The artificial intelligence integrated into the browser can make it more than just a simple web browser. For example, it can check email, buy tickets, etc., and it has the appropriate rights to do so. Researchers demonstrated, that the Comet AI was unable to distinguish between a hidden malicious text query on a page and a user manual. Even a comment under the content of a perfectly safe page can hack an AI browser.
“During our research on Comet, we discovered vulnerabilities reported by Perplexity that highlight the security challenges faced by agent-based AI implementations in browsers. The attack demonstrates how easy it is to manipulate AI assistants […]. The vulnerability we discuss in this post is in the way Comet handles webpage content: when users ask it to «Summarize this page», Comet passes a portion of it directly to its LLM, not distinguishing between user instructions and untrusted page content. This allows attackers to embed indirect query injection payloads that the AI will execute as commands,” Brave’s blog post says.
The attack is called indirect query injection. The text in an external source is deliberately passed off as a user manual.
The researchers gave a practical example of an attack in Comet browser. It can be implemented by look at in a video on Vimeo. A user visits a Reddit post with a comment that contains instructions for entering a code hidden behind a spoiler tag. They click the «Summarize this page» button in Comet. The Comet AI assistant sees and processes these hidden instructions, which in a few steps lead to the hijacking of the Perplexity account with a one-time login code.
Brave has developed simple guidelines for browser agent developers to prevent such attacks. The browser should distinguish between user instructions and website content, the model should independently check the consistency of tasks with the user, and the browser should isolate agent browsing from normal browsing.
In conclusion, the developers point out the fundamental problem of agent browsers with artificial intelligence: the agent should perform only those actions that meet the user’s wishes. As AI assistants become more and more powerful, indirect query injection attacks pose serious risks.
Контент сайту призначений для осіб віком від 21 року. Переглядаючи матеріали, ви підтверджуєте свою відповідність віковим обмеженням.
Cуб'єкт у сфері онлайн-медіа; ідентифікатор медіа - R40-06029.