Security researchers at Zenity Labs discovered two critical vulnerabilities in Perplexity's Comet AI browser. The flaws allowed attackers to access local files and hijack 1Password vaults by embedding malicious instructions in a Google Calendar event invitation. The attack exploited indirect prompt injection — Comet lacked cross-origin restrictions for the file:// protocol, and the AI agent could be manipulated into following instructions embedded in calendar entries or linked websites without user awareness. Perplexity was notified in October 2025, issued an initial patch in January 2026 that was bypassed, and released a second fix in February 2026. The incident highlights the broad attack surface of AI browsers, where any internet content a user interacts with can be fed into the LLM's context.