Zenity Labs
aidefend-sf0012
PerplexedBrowser: Comet Agent Hijack Against 1Password
- Autonomous Agents
- Edge & Client AI
- Data Exfiltration
- Credential & Identity Theft
Zenity demonstrated that a poisoned calendar invite could redirect Perplexity Comet from a routine meeting task into an installed and unlocked 1Password session. One path searched a Login item, revealed its username and password, and sent them through ordinary browser navigation. A second path changed the 1Password account password, obtained the account email and full Secret Key through the Emergency Kit flow, and exfiltrated that recovery material. The controlled proof of concept required no software vulnerability and relied on intended browser-agent capabilities plus shared authenticated state.