Comet’s Hidden API: A Browser Backdoor Waiting to Happen?

SquareX’s critical research on Comet’s hidden API reveals a security nightmare lurking in the AI Browser. This secret API lets extensions execute local commands, giving them full control over users’ devices—without consent! It’s a breach of trust that reverses decades of browser security principles. The race for AI browser dominance just got riskier.

Pro Dashboard

Hot Take:

Comet’s hidden API: It’s like finding a secret passage in your browser, except it leads to a dungeon full of potential security nightmares. Imagine your browser as a superhero, and then imagine it deciding one day to team up with the villains. That’s Comet with the MCP API—holy security breach, Batman! Someone better call the Justice League of cybersecurity before Comet turns into a full-blown supervillain.

Key Points:

  • SquareX discovered a hidden API in Comet that can execute local commands on users’ devices.
  • The MCP API allows Comet’s extensions to bypass traditional browser security measures.
  • Perplexity’s embedded extensions have persistent access to this API without user consent.
  • This vulnerability could lead to massive third-party risks if the API is exploited.
  • SquareX is urging for transparency and third-party audits to prevent similar threats.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?