Agentic browsers prompt-injected via near-invisible text in pages and screenshots
2025-comet-browser-screenshot-injection · 2025-10-21
Brave security researchers demonstrated that instructions hidden as near-invisible text in web pages and screenshots (e.g. faint text on a matching background) were processed as commands by agentic browsers including Perplexity Comet, enabling cross-domain actions with the user's authenticated privileges. Demonstrated as a proof of concept.
System
- Framework
- Perplexity Comet (agentic browser) and other AI browsers
- Tools
- browser, screenshot
- Autonomy
- supervised-autonomous
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/multimodal → unsafe-action/cross-domain-action
- Attack vector
- multimodal
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
Instructions were hidden as near-invisible text inside web page content and screenshots (e.g. faint light-blue text on a yellow background). When the user asked the assistant about the page or screenshot, the hidden text was processed as commands rather than as untrusted content.
Root cause
Agentic browsers execute with the user's authenticated privileges and treat untrusted page/image content as instructions, rendering protections like the same-origin policy irrelevant. Multimodal input widened the injection surface.
Contributing factors
- Page and image content shared the instruction channel with the user's request.
- The agent inherited the user's authenticated sessions across domains.
- No confirmation step before sensitive cross-domain actions.
Detection
Disclosed by Brave security research; corroborated by independent commentary (Simon Willison).
Recovery
Responsible disclosure to affected vendors (including Perplexity); vendors advised to harden against indirect and multimodal prompt injection.
Prevention
Separate untrusted page/image content from instructions; require explicit confirmation for sensitive cross-domain actions; constrain agent privileges; detect injected text in images.
Blast radius
- Data
- Demonstrated ability to trigger cross-domain actions with the user's authenticated privileges, potentially reaching banking, healthcare, corporate, email, and cloud-storage sites. confidential
- User harm
- Potential unauthorized actions and data access on behalf of the user across authenticated sessions; shown as a PoC. none-reported
- Scope
- users of affected agentic browsers
- Reversibility
- irreversible
References
- OWASP LLM
- LLM01 LLM06
- MITRE ATLAS
- AML.T0051
- Tags
- agentic-browser multimodal same-origin
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2025-comet-browser-screenshot-injection/
@misc{2025-comet-browser-screenshot-injection,
title = {Agentic browsers prompt-injected via near-invisible text in pages and screenshots},
year = {2025},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2025-comet-browser-screenshot-injection/}
}