Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet

Where is the profit going to come from?
“I’m used to seeing people misjudge and underestimate the severity of this problem, but it looks like the tide is finally turning there.”

“I strongly expect that the entire concept of an agentic browser extension is fatally flawed and cannot be built safely.”

Simon Willison