Weak phishing blocking
LayerX tested recent phishing URLs: Comet and Genspark stopped about 7%, while Chrome stopped about 47% and Edge about 54%. AI browsers that skip mature Safe Browsing-style filters leave users exposed.
COMET SAFETY CHECK · 2026
Not by default. Public research shows weak phishing blocking and agent hijack paths—treat Comet as high-privilege AI, not a hardened browser.
Perplexity Comet is an agentic browser that can act across tabs, email, and calendars. That power expands the blast radius when phishing or prompt injection succeeds. Tabbit offers a clearer, free Agent workflow on macOS and Windows if you want automation with more visible control.
Opens the official Tabbit product site for your edition.
RISK RADAR
The question is rarely “is it malware?”—it is whether agent permissions plus weaker web protections create a larger attack surface than Chrome.
LayerX tested recent phishing URLs: Comet and Genspark stopped about 7%, while Chrome stopped about 47% and Edge about 54%. AI browsers that skip mature Safe Browsing-style filters leave users exposed.
Security write-ups describe malicious links that instruct Comet’s AI to read sensitive context and exfiltrate it—no classic malware payload required. Agent browsers turn a click into a trusted insider.
Email, calendar, and shopping automations need deep access. Combined with public remarks about building richer user profiles for discovery/ads, privacy-conscious users treat Comet as high trust by default.
PUBLIC EVIDENCE
We summarize third-party reporting—not affiliate claims. Numbers and quotes come from published security blogs and privacy analyses visited during research.
LayerX Security
In a 100-URL phishing sample set, Comet allowed the vast majority through (~7% block rate), far behind Edge, Chrome, and Dia.
Tuta privacy analysis
Documents CometJacking-style flows where a crafted URL can steer the agent, then argues agent inbox/calendar access amplifies impact.
CEO / podcast coverage (via Tuta)
Perplexity leadership has discussed wanting browser-level context to understand users beyond the app—fuel for privacy concerns even when features feel helpful.
Security findings evolve. Verify current protections on official Perplexity channels before trusting any AI browser with critical accounts.
SAFER HABITS
Keep banking, work SSO, and agent experiments in different profiles or browsers.
Deny email/calendar connectors unless a task truly needs them—and revoke after.
Treat unexpected “open in Comet” or encoded URLs as hostile until proven otherwise.
Use Chrome/Edge with extensions you trust for payroll, taxes, and admin consoles.
Prefer tools that show step-by-step browser actions instead of opaque side-panel magic.
COMPARE
Safety is not only blocklists—it is permissions, visibility, and what happens when AI can act for you.
| Dimension | Comet | Chrome | Tabbit |
|---|---|---|---|
| Phishing baseline (LayerX snapshot) | ~7% block rate in tested set | ~47% block rate | Chromium-based browsing + Agent you can watch |
| Agent attack surface | High—AI can drive tasks & connectors | Low by default (extensions optional) | Agent mode designed for visible multi-tab workflows |
| Account connectors | Email/calendar integrations common | Manual / extension controlled | You choose when Agent touches sites |
| Privacy narrative | Public concern over profile building | Mature but ad-ecosystem known | Product focus on agent productivity, free public beta |
| Best for | Power users already in Perplexity | Everyday & sensitive sessions | Agent automation on Mac + Windows without Max-tier lock-in |
WHY TABBIT
Tabbit is not claiming “perfect security.” It is built so Agent work stays inspectable, multi-model, and free during public beta—useful when Comet’s risk profile feels wrong for your threat model.
Describe a workflow; Tabbit opens a tab group and executes steps you can review instead of trusting a silent sidebar.
Pick GPT, Claude, Gemini, and more (regional model sets differ)—reduce single-vendor lock-in inside the browser.
Public beta includes Agent mode without an invite code or Max-tier gate for core agentic browsing.
FAQ
No credible evidence labels official Perplexity Comet as malware. The concern is residual risk: weaker phishing defenses in tests and agent features that can be steered by malicious content.
Public LayerX results say no for phishing blocking—Chrome and Edge blocked far more samples than Comet in that study. Chrome remains safer for high-stakes browsing unless Comet’s protections improve.
A research name for attacks where a malicious URL or prompt manipulates Comet’s AI agent to read and leak sensitive context. It highlights how agentic browsers change the threat model.
Privacy analyses cite leadership comments about wanting richer browser context for personalization/ads. Exact telemetry changes over time—read the live privacy policy and limit connectors.
If you use it for research with sandboxed accounts, risk may be acceptable. If it has inbox, calendar, or banking access, tighten permissions or move sensitive work elsewhere.
For agentic automation with visible workflows on macOS and Windows, try Tabbit’s free public beta. Keep Chrome/Edge for sensitive admin tasks regardless of AI browser choice.

Tabbit runs multi-model Agent mode free on macOS and Windows—built for workflows you can watch, not opaque hijacks.