Security researchers have discovered that AI-powered browsers and agents from Perplexity, OpenAI, and Anthropic are vulnerable to covert prompt injection attacks. These attacks can manipulate AI agents to perform unauthorized actions, such as leaking user data or redirecting users to phishing sites. Tests revealed that hidden commands in web content could override user intent, with unprotected AI browsers succumbing to these attacks nearly 25% of the time. The affected platforms include Perplexity's Comet Browser, OpenAI's ChatGPT agents, and Anthropic's Claude extension. Experts advise users to limit permissions, avoid integrating passwords, and use traditional browsers for sensitive tasks until more robust security measures are implemented.