This is a random message on random Fridays about random topics. Typing fast, so pardon my random typos.
Today’s Focus: data extraction and code execution.
- Unseeable prompt injections in screenshots: more vulnerabilities in Comet and other AI browsers. An article from a series about issues with agentic browsers.
- CometJacking: How One Click Can Turn Perplexity’s Comet AI Browser Against You. A more detailed example of exploit agentic browser vulnerabilities.
- CVE-2025-59489: Arbitrary Code Execution in Unity Runtime. It is a cross-platform vulnerability for once. No longer can Linux and Android users feel left out.
Happy Friday!