Zenity Labs
aidefend-sf0017
PerplexedBrowser: Comet Local File Exfiltration
- Autonomous Agents
- Edge & Client AI
- Data Exfiltration
Zenity demonstrated in a controlled two-account environment that a weaponized Google Calendar invite could steer Perplexity Comet to an attacker-controlled site, redirect it into a supported file:// path, traverse local directories, open a file containing dummy credentials, and send the contents in an attacker URL's query parameters. The user only asked Comet to accept the invite, and the background variant produced no pre-exfiltration warning or confirmation. Perplexity later added a code-level block on agent access to file:// paths.