间接提示词攻击

Search documents
AI浏览器被曝重大安全漏洞,2分30秒内完成盗号
2 1 Shi Ji Jing Ji Bao Dao· 2025-08-26 08:32
Core Insights - The AI browser Comet from Perplexity has been exposed for significant security vulnerabilities, allowing attackers to extract sensitive user information without coding knowledge [1][2] - The vulnerability was first discovered by the security team of competitor Brave, who demonstrated that malicious commands could be executed through hidden instructions in forum comments [2] - Despite Perplexity's claims of having fixed the issue, subsequent tests by Brave indicated that the problem was not fully resolved, raising concerns about user data security [2][3] Company-Specific Insights - Perplexity's Comet browser integrates AI functionalities across various browsing scenarios, enabling users to interact with AI for tasks like reading screens and filling forms [1] - Brave has developed its own AI agent, Leo, but emphasizes that its functionality is limited to content analysis and does not execute independent operations [3] - Perplexity has publicly disputed claims regarding the security breach, asserting that the vulnerability was addressed before it was reported and that no user data was compromised [2] Industry Trends - The emergence of AI browsers has raised significant security concerns, with traditional security frameworks proving inadequate for new types of attacks [3][5] - The industry is witnessing a shift towards new security architectures, with Brave proposing a four-layer defense strategy for AI browsers to mitigate risks [5] - Major companies like Google, OpenAI, and Anthropic are avoiding features similar to Comet's, opting instead for virtual machine and cloud-based browser models to enhance security [5]