Blog
3 hours ago
Obscure MCP API in Comet Browser Breaches User Trust, Enabling Full Device Control via AI Browsers
SquareX released critical research exposing a hidden API in Comet that allows extensions in the AI Browser to execute local commands and gain full control over users' devices. The research reveals that Comet has implemented a MCP API (chrome.perplexity.mcp.addStdioServer) that allows its embedded extensions to execute arbitrary local commands.
Source: HackerNoon →