Skip to main content
VerifiedInjection

A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly

Brave's security team published in August 2025 that Perplexity's Comet browser agent could not distinguish the user's instruction from text on the page. In their demonstration, clicking summarise on a forum post made the agent read the user's account email, fetch a one time password from the mailbox, and post both back as a public reply.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0012
Kind
Injection
Jurisdiction
United States
Last verified
Added
  • Brave states that traditional browser protections such as the same origin policy and cross origin resource sharing are effectively useless against this class.
  • The payload was hidden behind a spoiler tag on a forum page, and the trigger was the user clicking summarise on that page.
  • The agent acted inside the user's already authenticated sessions, so origin based protections never applied.
  • Perplexity acknowledged within two days and shipped an initial fix, but Brave's retest the following day found it incomplete.
  • Brave published on 20 August 2025 noting the issue was not fully mitigated at that time.

Dimension by dimension

6 dimensions, each one stated, silent or open

Identity, Authorization, Delegation, Limits, Human approval, Revocation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
The agent had no way to tell whose instruction it was following, the user's or the web page's.Brave, Agentic browser security and indirect prompt injection in Comet, primary source, 20 August 2025.
AuthorizationSilent
Page content inherited the user's full authority across every site they were logged into.Brave, Agentic browser security and indirect prompt injection in Comet, primary source, 20 August 2025.
DelegationSilent
A request to summarise one page silently delegated far more than summarising.Brave, Agentic browser security and indirect prompt injection in Comet, primary source, 20 August 2025.
LimitsSilent
Nothing bounded cross site reach, so one forum page reached an account profile and a mailbox.Brave, Agentic browser security and indirect prompt injection in Comet, primary source, 20 August 2025.
Human approvalSilent
Reading a one time code and posting it publicly required no confirmation.Brave, Agentic browser security and indirect prompt injection in Comet, primary source, 20 August 2025.
RevocationOpen
A fix was shipped twice and the record shows the first was incomplete and the second unproven at publication.Brave, Agentic browser security and indirect prompt injection in Comet, primary source, 20 August 2025.

What it changes

For a team deploying an agent

A browser agent inherits every session you are signed into, which makes one summarise click an unbounded grant. The control that is missing is limits: a per site grant the user makes deliberately, with confirmation before the agent reads a mailbox or posts anything. Until a vendor can show you that, run a browsing agent in a profile that holds no logged in accounts you care about.

Sources

What this record was verified against

  1. Brave, Agentic browser security and indirect prompt injection in CometPrimary · 20 August 2025

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0012 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), a summarise request made the comet browser agent read a one time code from the user's mailbox and post it publicly.
APA
GAGE (Global Academy of Generative-AI Education). (2026). A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0012-comet-browser-agent-read-gmail-and-posted-it-back
MLA
"A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0012-comet-browser-agent-read-gmail-and-posted-it-back.
Chicago
GAGE (Global Academy of Generative-AI Education). "A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0012-comet-browser-agent-read-gmail-and-posted-it-back.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0012-comet-browser-agent-read-gmail-and-posted-it-back

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for United States and every injection record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.