Review

Perplexity Comet, reviewed: the AI browser works, and it has three named security vulnerabilities in under a year

Perplexity's Comet is a real, free, Chromium-based browser with an AI agent that can summarize a page, compare your open tabs, and even click through a checkout for you. It's also had three separately disclosed, named vulnerability classes since its 2025 launch, including one that could exfiltrate your email with a single link click. Most reviews cover one or the other. This one puts the features, the pricing, the independent security research, and what real users say after a week versus after seven months of daily use, in the same place.

به‌روزرسانی‌شده 5 Sept 202613 min read
Quick answer

Comet is free on Windows, Mac, Android, iOS, and iPad, no account required for basic browsing. Pro is $20/month or $200/year and unlocks the full AI agent plus Comet Plus (premium publisher content). Max is $200/month and adds unattended "Background Assistants" and an inbox-managing Email Assistant. Verified today against eesel AI's pricing breakdown and CNBC's coverage of the October 2025 free rollout.

The AI sidebar can summarize pages, videos, and PDFs, compare content across your open tabs, and take actions, clicking, filling forms, managing a shopping cart, reading Gmail and Calendar. Reviewers consistently say the summarization and cross-tab comparison work well; the agentic actions (forms, checkout, voice mode) are the reliably weak spot.

Three independently disclosed vulnerability classes hit Comet in under a year: CometJacking, a one-click exploit that could pull data from connected email and calendar and exfiltrate it, reported privately in August 2025 and published publicly in October 2025; PleaseFix (March 2026), indirect prompt injection via trusted-looking content like calendar invites; and Brave's own research identifying the architectural root cause, Comet feeding raw page content to its model without separating instructions from untrusted text. Perplexity's first response to CometJacking's private report was to say it found "no security impact."

User sentiment splits by how long people actually use it. Short-trial reviews (a week or two) tend to call it clunky and not different enough to switch for. MakeUseOf's seven-month review is the outlier and the most positive: the reviewer now does about 70% of daily browsing in Comet, but still won't use it for banking.

Diagram showing the CometJacking attack flow: a single malicious link causes Comet's agent to read page content as instructions, query connected services like email and calendar, and exfiltrate the data to an attacker's server, all without further clicks.
How CometJacking worked, per LayerX Security's August 2025 disclosure.

What Comet actually is, and what it costs today

Comet is a Chromium-based browser, meaning it uses the same rendering engine as Chrome and runs the same Chrome extensions, with an AI agent called Comet Assistant built into a persistent sidebar. Unlike a chatbot in a separate tab, the sidebar is tab-aware: it keeps context across your open tabs and can take actions in the page itself rather than just answering questions about it. It launched on Windows and Mac in July 2025, reached Android in November 2025, went free for everyone shortly after, and arrived on iPhone and iPad in March 2026, with a proper native iPadOS update, multi-window and Split View support, following in late April 2026.

           Free              Pro                        Max
--------------------------------------------------------------------------------
Price      $0                $20/mo or $200/yr           $200/mo
Access     Core browsing +   Full Comet Assistant +      Everything in Pro, plus
           limited agent,    Comet Plus (premium         unattended "Background
           ~5 Pro Searches/  publisher content,          Assistants," Perplexity
           day                normally $5/mo standalone)  Labs/Computer credits,
                                                           Email Assistant (Gmail/
                                                           Outlook auto-drafting)
Account    Not required for  Required                    Required

Verified against eesel AI's pricing breakdown and CNBC's October 2025
free-rollout coverage, checked 5 September 2026. Comet originally required
the $200/mo Max tier or an invite at its July 2025 launch; that gate was
removed within months.

What the agent can actually do

  • One-click summarization of pages, YouTube videos, PDFs, and social posts, without leaving the tab.
  • "@tab" referencing, pulling specific open tabs into a query so you can ask Comet to compare or synthesize across them, the feature MakeUseOf's independent review singles out as the standout for research-style use.
  • Split-view for side-by-side tabs, a built-in tracker and ad blocker, and customizable homepage widgets.
  • Agentic actions: clicking, navigating, filling out forms, and managing a shopping cart. Reviewers including PCMag and Lifehacker report this is the least reliable part, cart and checkout automation "often fails or is slower than manual browsing."
  • Email and calendar integration via a Gmail/Google Calendar connector, plus a separate Max-tier Email Assistant that drafts replies, applies labels, and can schedule meetings by CC on a thread.
  • Voice mode, which MakeUseOf's longer-term testing found underperforms the text interface and sometimes loops on a command instead of executing it.

The security record: three vulnerabilities in under a year

This is the part a feature-focused review tends to leave out, and it's the most consequential finding here. LayerX Security found CometJacking and reported it privately to Perplexity under responsible-disclosure terms on 27 August 2025: a single malicious link with a crafted URL parameter could instruct Comet's agent to pull data from its own memory or connected services, email, calendar, saved sessions, instead of searching the web, then base64-encode it and send it to an attacker's server. Perplexity's initial reply, per LayerX, was that it could identify "no security impact" and closed the report as not applicable. LayerX published the technical details publicly in October 2025, the same week Brave independently disclosed related Comet vulnerabilities of its own. BleepingComputer's coverage and Time's reporting both confirmed the mechanics: it required only one link click, no credentials, and no further interaction from the victim. Perplexity has since said it patched the issue and that it was never exploited in the wild.

That wasn't the only disclosure. In March 2026, security firm Zenity Labs published "PleaseFix," a set of indirect prompt-injection flaws where trusted-looking content, a calendar invite, for instance, could trigger unauthorized local file access and credential theft, with a reported compromise involving Comet's 1Password integration. The OECD.AI incident database logged it as a formal AI safety incident, not just a blog post claim. Separately, Brave's own security research identified the architectural root cause shared across these findings: when you ask Comet to summarize a page, it feeds the page's raw content straight to its underlying model without separating your instructions from untrusted content on that page. Hidden text, white text on a white background, HTML comments, near-invisible text inside an image, becomes an executable command as far as the model is concerned. eSecurity Planet, ActiveFence, and Aviatrix have each separately corroborated variants of local-file-leak and phishing-via-injection findings, which means this isn't one outlier researcher's claim, it's a pattern multiple independent security teams converged on within the same year.

Security firm Seraphic's enterprise guidance is the clearest signal of how seriously the industry is treating this: it recommends closing all tabs containing organizational data or active SSO sessions before using Comet's AI features at all, and disabling automated form-filling and workflow execution for any enterprise system, a striking admission that the safe way to use the browser's flagship feature at work is to turn it off. There's a business-model angle worth knowing too: Perplexity CEO Aravind Srinivas told the TBPN podcast that one reason Perplexity built a browser at all is "to get data even outside the app to better understand you," part of a stated plan to sell hyper-personalized ads, the same data-driven model as Chrome. Perplexity separately made a $34.5 billion bid for Google Chrome itself during 2025's antitrust proceedings, context for how central owning a browser is to the company's strategy.

None of this means Comet has caused confirmed, large-scale victim data loss as of this writing. What's true is narrower and still worth acting on: three independently discovered, named vulnerability classes surfaced in under a year, a security-industry consensus that the sidebar's core capability, reading page content and then acting on it, is structurally exploitable by design, and a first public response from Perplexity that downplayed the highest-profile one before patching it.

What real users say, and why a week and seven months disagree

Comet's Trustpilot page sits at 2.1 out of 5 from 20 reviews, a small enough sample to treat as a signal rather than a verdict, split sharply: roughly 85% one-star against 10% five-star, almost nothing in between. Positive reviews call the AI search "so much better than Google" and praise the uncluttered interface; negative ones describe features pulled behind a paywall after launching free, unresponsive support, and alleged account bans. Reddit's r/perplexity_ai thread on whether Comet is "any good or trash" surfaces a recurring UI complaint: the sidebar can't be resized or minimized in some builds, eating a chunk of the screen permanently.

Reviewer          Trial length     Verdict
------------------------------------------------------------------------------
XDA Developers     ~1 week          Returned to Chrome: "too cluttered and
                                     clunky," redundant with any standalone
                                     chatbot for the same tasks
HowToGeek          Extended use     Google Search still wins for quick lookups;
                                     Comet wins when you don't yet know the
                                     shape of your question
efficient.app      Hands-on         "Only totally free agentic browser," good
                                     for research/shopping, "rough around the
                                     edges"
MakeUseOf          7 months         The outlier: ~70% of daily browsing now in
                                     Comet, reliability "markedly improved" -
                                     but still uses Edge for banking

Sources: XDA Developers (xda-developers.com), HowToGeek
(howtogeek.com), efficient.app/apps/comet, MakeUseOf
(makeuseof.com), checked 5 September 2026.

The pattern across every source: cross-tab research and one-click summarization is the consistently praised feature, voice mode and multi-step agent actions are the consistently weak one, and Comet uses more RAM than Edge or Chrome across every review that measured it. Where reviewers genuinely disagree is duration-dependent: short trials read as "not different enough to switch," while MakeUseOf's seven-month view is the only one in this set that calls it a daily driver, and it's explicit that this verdict is scoped to people already inside Perplexity's ecosystem, not a universal recommendation to replace Chrome.

Comet vs the competition: Gemini in Chrome, and the ChatGPT Atlas browser that no longer exists

Worth noting up front, since it changes the competitive picture: OpenAI shut ChatGPT Atlas down on 9 August 2026, less than a year after its October 2025 launch, folding its browser-based agentic features directly into ChatGPT itself rather than continuing it as a separate app. Atlas never shipped beyond macOS, Windows and mobile versions were promised at launch and never arrived. Any comparison written before August 2026 that still lists Atlas as a standalone rival is out of date; the real second axis of comparison today is Gemini in Chrome, a feature built into Chrome rather than a separate browser.

                  Comet                    Gemini in Chrome
--------------------------------------------------------------------------
Architecture       Standalone Chromium       A feature inside Chrome
                    browser                   itself, not a new browser
Autonomy            Agent mode, mixed         "Auto Browse" for multi-step
                    reliability on forms/      tasks (hotel/flight research,
                    checkout                   forms), Pro/Ultra subs only
Specialty            Research/citation         Multi-tab comparison,
                     accuracy (Perplexity's    "Personal Intelligence"
                     answer-engine heritage)   memory (planned)
Platform reach       Windows, Mac, Android,    Chrome on Android first,
                     iOS, and iPad             expanding from there
Named security       Three disclosed           None as widely documented
incidents            vulnerability classes     as Comet's as of this
                     in under a year           writing

The one-line summary: Comet leans toward stronger research and citation accuracy thanks to Perplexity's answer-engine heritage, while Gemini in Chrome is the option that doesn't require leaving your existing browser at all, at the cost of gating its agentic "Auto Browse" feature to paying subscribers.

Is Comet actually useful for research and document work?

Partially, and it's worth separating what's independently confirmed from what's only claimed. The @tab feature, confirmed directly by MakeUseOf's hands-on testing, genuinely helps: referencing multiple open tabs in one query for synthesis is close to a multi-source research workflow, just browser-native instead of notebook-native. Marketing-adjacent sources claim Comet also handles direct PDF upload, arXiv/DOI link ingestion, scanned-paper OCR, and citation formatting in APA, IEEE, Chicago, or MLA style, but none of the independent reviews in this piece, PCMag, MakeUseOf, HowToGeek, or XDA, confirm citation export specifically. Treat that claim as plausible but unverified until you've tried it yourself.

The more useful framing for this audience is the difference in trust model, not a feature checklist. Gemini Notebook's source-grounding is scoped to documents you explicitly upload, a closed corpus with nothing else in scope. Comet operates on the open web, which is exactly the surface CometJacking and PleaseFix exploited, a malicious page or calendar invite the agent encounters while browsing. A tool that only ever reads what you handed it carries a fundamentally smaller attack surface than one built to read and act on anything it comes across.

When not to use Comet

  • For banking or anything tied to a financial account. Even MakeUseOf's most positive, longest-duration review keeps a separate browser for this specifically.
  • On a work machine with active SSO sessions or organizational data, per Seraphic Security's own enterprise guidance to close such tabs before enabling Comet's AI features.
  • If you're relying on formatted citation export for academic work. That claim isn't independently confirmed; verify it yourself before trusting a bibliography Comet generates.
  • If checkout automation is the reason you want it. Multiple reviewers report cart and form-filling as unreliable enough to be slower than doing it manually.
  • If you're uncomfortable with a company that has stated an intent to build ad-targeting profiles from browsing data outside the app itself.

People also ask

Is Perplexity Comet free?

Yes, since October 2025, on Windows, Mac, and Android, with iOS following in March 2026. The free tier includes core browsing and a limited agent (about 5 Pro Searches a day). Pro ($20/month or $200/year) and Max ($200/month) unlock the full AI agent and additional automation.

Is Perplexity Comet safe to use?

There's no confirmed mass-exploitation incident, but three independently disclosed vulnerability classes (CometJacking, PleaseFix, and Brave's prompt-injection research) surfaced within about a year, and security researchers agree the underlying architecture, reading page content and acting on it, is structurally exploitable. Avoid it for banking and for work accounts with sensitive data.

What is CometJacking?

A vulnerability disclosed by LayerX Security in August 2025 where a single malicious link with a crafted URL parameter could make Comet's agent pull data from connected services like email and calendar and exfiltrate it to an attacker, without further interaction from the victim. Perplexity initially said it had no security impact, then patched it.

Does Comet work with Chrome extensions?

Yes. Comet is built on Chromium, the same engine Chrome uses, so existing Chrome extensions are compatible.

How is Comet different from Gemini in Chrome? What happened to ChatGPT Atlas?

Comet is a standalone browser built around research and citation-style answers. Gemini in Chrome isn't a separate browser at all, it's a feature added to Chrome itself, with its agentic "Auto Browse" capability limited to paying subscribers. ChatGPT Atlas, OpenAI's competing standalone browser, was shut down on 9 August 2026, less than a year after launch, with its features folded into ChatGPT directly.

Can Comet make purchases or fill out forms automatically?

Yes, that's part of its agent mode, but multiple independent reviews report the feature is unreliable, cart and checkout automation sometimes fails or takes longer than doing it manually.

notebooklm-to-pdf.comهمه راهنماها

NotebookLM خود را با یک کلیک خروجی بگیرید

افزونه رایگان Chrome. PDF، Word و Markdown. روی دستگاه شما رندر می‌شود — چیزی آپلود نمی‌شود.

ادامه مطالعه