Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Perplexity

Perplexity Vendor Cyber Rating & Cyber Score

perplexity.ai

The most powerful answer engine. Powering curiosity with answers backed by up-to-date sources. This is where knowledge begins.


Perplexity A.I CyberSecurity Scoring

Perplexity
Company Information
Website:https://www.perplexity.ai
Employees number:1,622
Number of followers:1,361,092
NAICS:5112
Industry Type:Software Development
Homepage:perplexity.ai
Perplexity Risk Score (AI oriented)
Between 700 and 749
logo
PerplexitySoftware Development
Updated:
12/06/2026
735/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Perplexity Global Score (TPRM)
xxxx
logo
PerplexitySoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Perplexity
PerplexityModerate
Current Score
735Ba (MODERATE)
01000
5 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
734Before Incident
MAY 2026
733Before Incident
APRIL 2026
733Before Incident
MARCH 2026
735Before Incident
Vulnerability
03 Mar 2026Perplexity
Perplexity: 'The attack requires no exploit, no user clicks, and no explicit request forsensitive actions': Experts say Perplexity's AI Comet browser can be hijacked to steal your passwords

Zero-Click AI Prompt Injection Flaw in Comet Browser Exposed Sensitive Data

731After Incident
CRITICAL-4
PER1772547904
Zero-Click AI Prompt Injection Flaw in Comet Browser Exposed Sensitive Data Researchers at Zenity uncovered PleaseFix, a zero-click indirect prompt injection vulnerability in Perplexity’s AI-powered Comet browser, allowing attackers to exfiltrate passwords and sensitive files without user interaction. The flaw stemmed from AI agents’ inability to differentiate between data and instructions. By embedding malicious prompts in seemingly benign calendar invites such as meeting requests or interview schedules attackers could trick the AI into executing hidden commands when users asked Comet to summarize or prepare for the event. In one demonstration, the AI was manipulated to scan local files for documents named "passwords" and transmit the contents to an external server. Another scenario targeted password managers, silently extracting stored credentials. The attack required no user action beyond adding the calendar invite, making it particularly stealthy. Victims remained unaware as the AI operated in the background, turning the tool into an unwitting accomplice for data theft. Following responsible disclosure, Perplexity patched the vulnerability by restricting the browser’s AI agents from autonomously accessing file:// paths, preventing them from reading the local filesystem. While users retain manual access to these files, the AI can no longer navigate or interact with them, regardless of prompts.
INCIDENT DETAILS -
TYPE
AI Prompt Injection
IMPACT
Data Compromised: Passwords, sensitive filesSystems Affected: Comet browser (AI-powered)Identity Theft Risk: High
DATA BREACH
PasswordsSensitive filesSensitivity Of Data: HighData Exfiltration: Yes (to external server)Documents named 'passwords'Password manager credentials
FEBRUARY 2026
734Before Incident
JANUARY 2026
734Before Incident
DECEMBER 2025
732Before Incident
NOVEMBER 2025
735Before Incident
Vulnerability
18 Nov 2025Perplexity
Perplexity

HashJack: Indirect Prompt Injection Exploit in AI-Powered Browsers

731After Incident
CRITICAL-4
PER3034930112625
Perplexity’s AI-powered browser Comet was exposed to HashJack, a critical indirect prompt injection vulnerability exploiting URL fragments (after the ‘#’ symbol) to execute hidden malicious instructions. The flaw allowed threat actors to bypass traditional security systems—such as server logs, network monitoring, and content security policies—by embedding deceptive prompts (e.g., callback phishing, data exfiltration, misinformation, malware guidance, medical harm, and credential theft) that appeared as legitimate AI-generated responses. Users were tricked into divulging sensitive financial/personal data, installing backdoors, or following harmful medical advice, all while the attack remained undetected due to client-side processing of URL fragments.Perplexity initially dismissed the report but later classified it as critical severity (P1), deploying fixes by November 18, 2025. The incident highlights systemic risks in AI browsers, where LLM susceptibility to prompt injection and flawed URL-handling design enable large-scale deception, financial fraud, and operational disruptions. The attack’s stealth and automation potential—particularly in agentic browsers—posed severe reputational, financial, and trust-based damages, with long-term implications for user safety and regulatory compliance.
INCIDENT DETAILS -
TYPE
Prompt InjectionAI ManipulationClient-Side AttackSocial Engineering
MOTIVATION
Financial GainData TheftMisinformationCredential HarvestingMalware DistributionMedical Harm
IMPACT
Sensitive Financial DataPersonal DataCredentialsAI-Powered Browsers (Perplexity Comet, Microsoft Edge Copilot, Google Gemini for Chrome)User DevicesIoT Devices (via Malware Guidance)Automated Data ExfiltrationUnauthorized AI Assistant ActionsUser Trust ErosionHigh (Due to AI Manipulation and Undetectable Attacks)High (Via Credential Theft and PII Exposure)High (Financial Data Exfiltration)
DATA BREACH
Financial DataPersonal DataCredentialsMedical Information (via Misinformation)IoT Device AccessSensitivity Of Data: HighAutomated (via Agentic Browsers like Comet)CredentialsFinancial RecordsPersonal Details
OCTOBER 2025
738Before Incident
Vulnerability
01 Oct 2025Perplexity
Perplexity, OpenAI and Brave Software: AI-powered browsers: The new frontier of enterprise security risks

AI-Powered Browsers Introduce New Enterprise Security Risks

734After Incident
CRITICAL-4
OPEBRAPER1781289020
AI-Powered Browsers Introduce New Enterprise Security Risks Security researchers have uncovered vulnerabilities in AI-powered browsers and assistants, exposing enterprises to heightened risks of data breaches and unauthorized access. A key concern is prompt injection attacks, where malicious instructions embedded in web pages, emails, or documents trick AI agents into executing unintended commands bypassing security guardrails. Last year, Brave Software revealed that Perplexity’s Comet AI assistant failed to distinguish between legitimate user commands and hidden malicious prompts, potentially exposing sensitive data like bank accounts, emails, and cloud storage. While Perplexity later implemented real-time prompt injection classifiers, OpenAI acknowledged in December that such threats remain persistent, comparing them to social engineering attacks with no definitive solution. Gartner has advised CISOs to block AI browsers with agentic capabilities until enterprise-ready alternatives emerge, citing privacy risks from cloud-stored browsing data and third-party tracking. A 2025 University of California, Davis study found that generative AI browser assistants collect and share personal and sensitive information with both first-party servers and third-party trackers like Google Analytics. Unlike traditional browser threats, prompt injection attacks are easier to execute using natural language, requiring no advanced technical skills. A 2025 Gartner report found that 32% of organizations have already experienced such attacks on GenAI applications. Palo Alto Networks warns that these attacks can manipulate AI agents into leaking data, escalating privileges, or abusing connected systems often undetected by conventional security tools. Enterprises face additional risks from shadow AI unauthorized AI browser usage that creates blind spots for IT teams. IBM’s 2025 Cost of Data Breach report attributed 20% of breaches to shadow AI incidents. Compounding the issue, AI agents often operate with excessive permissions, violating the principle of least privilege, while Model Context Protocol (MCP) supply chain attacks introduce new attack vectors through third-party API integrations. To mitigate risks, security experts recommend: - Isolating agentic AI capabilities from routine browsing to prevent accidental exposure. - Enterprise-grade AI browsers with runtime security to monitor prompts and block malicious interactions. - Step-up MFA and human approval for sensitive actions, ensuring oversight before data transfers or transactions. - Defensive AI agents to detect anomalous behavior in primary browser agents. While AI browsers enhance productivity, their broad access and evolving attack surfaces demand stricter governance, visibility, and security controls to prevent exploitation.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessPrompt Injection Attack
MOTIVATION
Data exfiltrationPrivilege escalationFinancial gain (via dark web sales)
IMPACT
Bank account detailsEmailsCloud storage dataPersonal and sensitive informationAI-powered browsers/assistantsEnterprise cloud storageThird-party tracking systemsUnauthorized data accessPrivilege escalationUndetected malicious activityPrivacy risksData exposure concerns
DATA BREACH
Bank account detailsEmailsCloud storage dataPersonal and sensitive informationSensitivity Of Data: High
SEPTEMBER 2025
738Before Incident
AUGUST 2025
737Before Incident
JULY 2025
736Before Incident
JUNE 2024
778Before Incident
Breach
01 Jun 2024Perplexity
Perplexity AI

Perplexity AI Investigation for Breaching AWS Rules

721After Incident
MEDIUM-57
PER449070624
Perplexity AI is under investigation by Amazon Web Services (AWS) for potentially breaching AWS rules by ignoring the Robots Exclusion Protocol and scraping content from websites that attempted to block its access. This protocol, which is widely respected though not legally binding, was dismissed by Perplexity as it accessed data from multiple websites including Condé Nast properties through scraping practices. Companies affected have reported unauthorized crawling by an IP address linked to Perplexity, raising concerns about data use and adherence to AWS's terms of service. As a result, the integrity and legitimacy of the content used by Perplexity's AI search service are in question, reflecting poorly on their operations.
INCIDENT DETAILS -
TYPE
Data Scraping
MOTIVATION
Data Collection
IMPACT
Website ContentOperational Impact: Questionable Integrity and Legitimacy of AI Search ServiceBrand Reputation Impact: Poor Reflection on Operations
DATA BREACH
Type Of Data Compromised: Website Content
JUNE 2020
780Before Incident
Cyber Attack
16 Jun 2020Perplexity
Perplexity

CometJacking Attack Targeting Perplexity's AI Browser Comet

764After Incident
HIGH-16
PER1592715100425
Cybersecurity researchers uncovered CometJacking, a novel prompt injection attack targeting Perplexity’s AI-powered browser, Comet. The attack exploits a malicious URL to hijack the embedded AI assistant, siphoning sensitive data—including emails, calendars, and connected services—without requiring credential theft, as the browser already has authorized access. The attack leverages Base64 obfuscation to bypass Perplexity’s data exfiltration protections, transmitting stolen information to an attacker-controlled endpoint in a single click. The technique weaponizes the ‘collection’ URL parameter, tricking the AI into executing hidden prompts that extract data from the user’s linked accounts (e.g., Gmail). While Perplexity dismissed the findings as having ‘no security impact’, the attack demonstrates how AI-native tools can circumvent traditional defenses, turning trusted assistants into insider threats. Researchers warn this could enable large-scale data theft if exploited in phishing campaigns, particularly in enterprise environments where AI browsers are integrated. The attack mirrors prior techniques like Scamlexity (2020), where browsers were manipulated into interacting with phishing pages autonomously. Experts emphasize the urgent need for security-by-design in AI agents to prevent prompt-based exploits from becoming widespread threats.
INCIDENT DETAILS -
TYPE
Prompt InjectionData ExfiltrationAI Hijacking
MOTIVATION
Data TheftUnauthorized Data AccessExploitation of AI Tools
IMPACT
Email DataCalendar DataConnected Service DataPerplexity Comet AI BrowserPotential Erosion of Trust in AI Tools
DATA BREACH
Email DataCalendar DataConnector Service DataHigh (Authorized Access to Connected Services)Base64-Encoded Data Transmitted to Attacker-Controlled EndpointBypassed via Obfuscation (Base64)Potential (Depending on Connected Services)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Perplexity ?
?
What was Perplexity's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Perplexity's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Perplexity's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Perplexity's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Perplexity's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Perplexity's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Perplexity's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Perplexity's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Perplexity's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Perplexity's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Perplexity's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Perplexity's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Perplexity ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Perplexity's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Perplexity Cyber Scoring History | Rankiteo