Perplexity responds to Comet browser vulnerability claims, argues “fake news”


  • SquareX accused Perplexity’s Comet browser of exposing a hidden MCP API that could enable local command execution
  • Perplexity rejected the claims as “entirely false,” stressing the API requires developer mode, user consent, and manual sideloading
  • SquareX countered, saying Comet was silently updated after its proof‑of‑concept, and that external researchers replicated the attack

Cybersecurity company SquareX recently accused Perplexity of keeping a major vulnerability in its AI browser, Comet – the latter has now responded, saying the research report is “entirely false” and part of a growing “fake security research” problem.

SquareX had said it found a hidden API in the Comet browser, capable of executing local commands. That API, named MCP API, allows its embedded extensions to execute arbitrary local commands on users’ devices, capabilities that traditional browsers explicitly prohibit.



Source

Categories: IT News

Leave a Reply

Your email address will not be published. Required fields are marked *