agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: corroborated status: factual

Agentic browsers prompt-injected via near-invisible text in pages and screenshots

2025-comet-browser-screenshot-injection · 2025-10-21

Brave security researchers demonstrated that instructions hidden as near-invisible text in web pages and screenshots (e.g. faint text on a matching background) were processed as commands by agentic browsers including Perplexity Comet, enabling cross-domain actions with the user's authenticated privileges. Demonstrated as a proof of concept.

System

Framework
Perplexity Comet (agentic browser) and other AI browsers
Tools
browser, screenshot
Autonomy
supervised-autonomous

Classification

Primary class
prompt-injection
Chain
prompt-injection/multimodal → unsafe-action/cross-domain-action
Attack vector
multimodal
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

Instructions were hidden as near-invisible text inside web page content and screenshots (e.g. faint light-blue text on a yellow background). When the user asked the assistant about the page or screenshot, the hidden text was processed as commands rather than as untrusted content.

Root cause

Agentic browsers execute with the user's authenticated privileges and treat untrusted page/image content as instructions, rendering protections like the same-origin policy irrelevant. Multimodal input widened the injection surface.

Contributing factors

  • Page and image content shared the instruction channel with the user's request.
  • The agent inherited the user's authenticated sessions across domains.
  • No confirmation step before sensitive cross-domain actions.

Detection

Disclosed by Brave security research; corroborated by independent commentary (Simon Willison).

Recovery

Responsible disclosure to affected vendors (including Perplexity); vendors advised to harden against indirect and multimodal prompt injection.

Prevention

Separate untrusted page/image content from instructions; require explicit confirmation for sensitive cross-domain actions; constrain agent privileges; detect injected text in images.

Blast radius

Data
Demonstrated ability to trigger cross-domain actions with the user's authenticated privileges, potentially reaching banking, healthcare, corporate, email, and cloud-storage sites. confidential
User harm
Potential unauthorized actions and data access on behalf of the user across authenticated sessions; shown as a PoC. none-reported
Scope
users of affected agentic browsers
Reversibility
irreversible

References

OWASP LLM
LLM01 LLM06
MITRE ATLAS
AML.T0051
Tags
agentic-browser multimodal same-origin

Sources

Cite this incident

@misc{2025-comet-browser-screenshot-injection,
  title = {Agentic browsers prompt-injected via near-invisible text in pages and screenshots},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-comet-browser-screenshot-injection/}
}