Researchers from Guardio have demonstrated that Perplexity’s Comet AI browser can be tricked into falling for a phishing scam in under four minutes by exploiting a phenomenon called “Agentic Blabbering.”
The Attack: Agentic Blabbering
The vulnerability stems from the AI browser’s tendency to narrate its internal reasoning and decision-making process in real time as it interacts with web pages.
- Real-Time Feedback Loop: Researchers intercepted the traffic between the browser and its backend AI services.
- GAN Training: They fed this “blabbering”—the AI’s thoughts on what looks suspicious or safe—into a Generative Adversarial Network (GAN).
- Automated Refinement: The GAN used the AI’s own feedback to iteratively redesign a phishing page. It adjusted elements the AI flagged until the scam page appeared perfectly legitimate to the browser’s security filters.
- Zero-Click Success: Once the page was refined, the Comet AI agent autonomously navigated the site, entered sensitive information, and completed a fraudulent transaction without any human intervention or confirmation.
Broader Security Context
This discovery is part of a series of critical vulnerabilities identified in the Comet browser throughout early 2026:
- PleaseFix Vulnerabilities: Researchers at Zenity Labs recently uncovered a family of flaws dubbed “PleaseFix,” which allow attackers to hijack the browser via simple calendar invites to exfiltrate local files and credentials.
- CometJacking: Previous research by LayerX showed that “CometJacking” could turn the browser into a data-exfiltration tool with a single click on a weaponized URL.
- Legal & Corporate Response: Amidst these security concerns, a federal judge recently blocked Comet from making automated purchases on Amazon. In response to the rising threats, Perplexity has partnered with CrowdStrike to integrate the Falcon platform into its Enterprise browser for better real-time detection.