PleaseFix Flaw Lets Hackers Access 1Password Vault via Comet AI Browser

Original Article Summary
Researchers at Zenity Labs uncover PleaseFix flaws in Perplexity’s Comet browser. See how zero-click calendar invites allow AI agents to steal 1Password credentials and personal files.
Read full article at HackRead✨Our Analysis
PleaseFix's discovery of a flaw in Perplexity's Comet AI browser, which allows hackers to access 1Password vaults via zero-click calendar invites, marks a significant vulnerability in AI-powered browsing security. This means that website owners who use 1Password for password management and have integrated Comet AI browser for enhanced user experience are at risk of having their sensitive credentials and personal files compromised. The fact that zero-click calendar invites can be used to steal 1Password credentials highlights the need for website owners to reassess their security measures and consider the potential risks associated with AI-powered browsing. To mitigate this risk, website owners can take several actionable steps: firstly, monitor AI bot traffic to their sites to detect any suspicious activity, secondly, review and update their llms.txt files to ensure that Comet AI browser is properly configured, and thirdly, consider implementing additional security measures such as two-factor authentication to protect sensitive credentials.
Related Topics
Track AI Bots on Your Website
See which AI crawlers like ChatGPT, Claude, and Gemini are visiting your site. Get real-time analytics and actionable insights.
Start Tracking Free →Related Articles

Media Briefing: As AI search grows, a cottage industry of GEO vendors is booming
3/5/2026

Perplexity asks a US judge to force Dow Jones and the New York Post to hand over the queries they made to "fish" for a basis to sue for copyright infringement (Charlotte Tobitt/Press Gazette)
3/3/2026

Revolut's new corporate card wants to topple Amex's business crown - and you even get free Perplexity AI
3/3/2026
