Quick answer: Perplexity Comet is a real, functional AI browser, but it is not fully safe for sensitive activity yet. Independent security researchers have found genuine vulnerabilities, including a prompt injection attack called CometJacking, that could let a malicious webpage hijack the browser’s AI assistant. Use it for general browsing in a separate profile, but avoid banking, primary passwords, and sensitive accounts until its security track record improves.
Comet is Perplexity’s answer to a simple question: what if your browser could act for you, not just display pages? It can summarise articles, manage tabs, write emails, and even complete purchases on your behalf. That level of access is exactly why “is Perplexity Comet safe” is worth asking properly before you make it your daily browser.
What Is Perplexity Comet?
Comet is a Chromium-based browser built by Perplexity AI, first released in July 2025 and made free to download from October 2025. It integrates Perplexity’s AI search directly into browsing, with an assistant that can generate summaries, draft replies, and carry out multi-step tasks such as booking something or comparing products across tabs. Its reach grew quickly after Perplexity struck a 400 million US dollar deal to power Snapchat’s search, putting Comet-style AI browsing in front of an enormous audience.
The Real Security Issue: CometJacking
In 2025, security researchers at LayerX disclosed a vulnerability they named CometJacking. The core problem is that Comet’s AI assistant can be manipulated by a single malicious click, tricking it into ignoring its normal instructions and instead following commands embedded on a webpage. Once hijacked, the AI can be directed to access data it has permission to see, such as connected email or documents, and send it to a server controlled by the attacker, without any obvious sign to the user that something went wrong.
LayerX reported the finding to Perplexity through a responsible disclosure process. According to their published research, Perplexity initially assessed it as having no security impact. Independent researchers at another firm, SquareX, later identified a related issue involving Comet’s MCP API that could be used to reach beyond the browser sandbox toward the device itself.
This is not a single isolated bug. Security firm Guardio and browser maker Brave have separately published audits highlighting Comet’s exposure to phishing and code injection, and academic researchers presenting at the ICLR 2026 Workshop on Agents in the Wild found that while Comet resisted a simple prompt injection test, it could still be influenced by cross-origin conversation or browsing-history context in some scenarios, and noted that resisting a basic test does not prove resistance to more sophisticated attacks.
Why This Matters More for an AI Browser Than a Normal One
A standard browser executes what you tell it to do. An agentic browser like Comet is designed to interpret instructions and act with some autonomy, using access you have granted it to your email, documents, browsing history, or connected accounts. That autonomy is the entire value proposition, and it is also exactly what makes a successful prompt injection attack more damaging than it would be against a browser with no AI layer at all.
Perplexity has publicly acknowledged this is an active area of work, describing a defence-in-depth approach involving detection, guardrails, user confirmation steps, and tool-policy enforcement, and treats prompt injection as an ongoing security challenge rather than a solved problem.
What Is Actually Safe to Do in Comet Right Now
Not every use case carries the same risk. A reasonable, evidence-based approach looks like this:
- Lower risk: General web browsing, reading articles, casual research using Comet’s summarisation features.
- Moderate risk: Checking email with two-factor authentication enabled, as long as you stay alert to unexpected behaviour.
- Avoid for now: Banking, primary password manager access, anything involving stored payment details, or high-stakes work accounts, until Comet’s isolation and prompt injection defences have a longer track record.
Independent testing has also found Comet’s AI assistant is measurably more exposed to scam pages than a standard browser, so treating unfamiliar links and pop-ups with extra caution matters more here than in a conventional browser.
Practical Steps If You Want to Try Comet
- Use a separate browser profile, not your primary identity, password manager, or main work accounts.
- Keep two-factor authentication enabled on any account you do access through Comet.
- Avoid granting the AI assistant broad permissions to your email, documents, or connected accounts until you understand exactly what it can act on.
- Be cautious with unfamiliar links and pop-ups, since Comet has shown higher exposure to scam content in independent testing than standard browsers.
- Keep the browser updated. Perplexity has continued patching disclosed issues, and staying current matters more for an actively evolving security surface like this one.
Comet’s Accuracy: A Separate but Related Concern
Beyond security, some users researching intensive tasks have noticed Comet occasionally presenting sources or references that do not actually exist, a known limitation of AI search tools generally, reported to occur in a meaningful share of intensive research sessions. This does not make Comet unsafe in the security sense, but it is worth knowing if you plan to rely on it for research where accuracy genuinely matters. Verify any important reference independently rather than trusting it outright.
Common Questions About Perplexity Comet
Is Perplexity Comet safe to use?
It is safe for general, low-stakes browsing in a separate profile. It is not yet recommended for banking, primary passwords, or sensitive accounts, due to documented prompt injection vulnerabilities including CometJacking.
What is CometJacking?
A disclosed vulnerability where a single malicious click can manipulate Comet’s AI assistant into ignoring its normal instructions and following commands hidden on a webpage instead, potentially exposing data the assistant has access to.
Has Perplexity fixed the security issues?
Perplexity has acknowledged prompt injection as an active security challenge and describes ongoing mitigation work, but independent researchers continue to find related issues, so treat this as an evolving situation rather than a solved one.
Is Comet worth trying at all?
Yes, for general browsing and casual AI assistance in a separate profile. Wait before relying on it for anything involving sensitive accounts or stored payment information.
How is Comet different from a normal Chromium browser?
Comet adds an AI assistant that can act autonomously on your behalf, summarising pages, managing tabs, and completing tasks, which is also what creates the additional attack surface a standard browser does not have.
The Bottom Line
Perplexity Comet is a genuinely capable AI browser, not a scam or a hollow product. But “safe” has to be judged against what it actually does: an AI assistant with real access acting on your behalf, which multiple independent security teams have shown can be manipulated through prompt injection. Use it for everyday browsing in an isolated profile, keep sensitive accounts out of it for now, and revisit that decision as Perplexity’s security track record develops further.
