{"id":179722,"date":"2025-12-07T18:24:07","date_gmt":"2025-12-07T18:24:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/179722\/"},"modified":"2025-12-07T18:24:07","modified_gmt":"2025-12-07T18:24:07","slug":"alert-zero-click-wiper-ai-browser-exploit-mass-deletes-google-drive-files","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/179722\/","title":{"rendered":"Alert\u2014\u2018Zero\u2011Click Wiper\u2019 AI Browser Exploit Mass\u2011Deletes Google Drive Files"},"content":{"rendered":"<p>A polite email asking an AI browser to \u201corganize your Drive\u201d can silently wipe your files. No phishing link or suspicious attachment required. Just a friendly request that turns an automated assistant into a destructive tool.<\/p>\n<p>Security researcher Amanda Rousseau at Straiker STAR Labs <a class=\"color-link\" href=\"https:\/\/www.straiker.ai\/blog\/from-inbox-to-wipeout-perplexity-comets-ai-browser-quietly-erasing-google-drive\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.straiker.ai\/blog\/from-inbox-to-wipeout-perplexity-comets-ai-browser-quietly-erasing-google-drive\" aria-label=\"revealed this week\">revealed this week<\/a> that Perplexity\u2019s Comet browser, an AI-powered browser that automates email and cloud storage tasks, can be manipulated into mass-deleting Google Drive files through what she calls a \u201czero-click Google Drive Wiper\u201d attack.<\/p>\n<p>The technique exploits how AI browser agents interpret instructions. When a user tells Comet to \u201ccheck my email and complete all my recent organization tasks,\u201d the browser scans the inbox and follows whatever it finds. An attacker can send an email with polite, step-by-step instructions\u2014organize the Drive, delete loose files, review changes\u2014that the agent treats as legitimate housekeeping and executes without further confirmation.<\/p>\n<p>\u201cThe result: a browser-agent-driven wiper that moves critical content to trash at scale, triggered by one natural-language request from the user,\u201d Rousseau wrote in the <a class=\"color-link\" href=\"https:\/\/www.straiker.ai\/blog\/from-inbox-to-wipeout-perplexity-comets-ai-browser-quietly-erasing-google-drive\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.straiker.ai\/blog\/from-inbox-to-wipeout-perplexity-comets-ai-browser-quietly-erasing-google-drive\" aria-label=\"research blog\">research blog<\/a>. \u201cOnce an agent has OAuth access to Gmail and Google Drive, abused instructions can propagate quickly across shared folders and team drives.\u201d<\/p>\n<p>What makes this attack effective is its tone. The attacker email uses phrases like \u201ctake care of,\u201d \u201chandle this,\u201d and \u201cdo this on my behalf,\u201d shifting ownership to the agent and nudging it toward compliance. Rousseau found that polite, sequential instructions reduce pushback from the AI model, which treats the workflow as routine productivity work rather than a potential threat.<\/p>\n<p>The attack doesn\u2019t rely on jailbreak techniques or traditional prompt injection. Instead, it succeeds by being nice.<\/p>\n<p>A separate but related threat emerged in late November when Cato Networks <a class=\"color-link\" href=\"https:\/\/www.catonetworks.com\/blog\/cato-ctrl-hashjack-first-known-indirect-prompt-injection\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.catonetworks.com\/blog\/cato-ctrl-hashjack-first-known-indirect-prompt-injection\/\" aria-label=\"disclosed HashJack\">disclosed HashJack<\/a>, a technique that hides malicious prompts in the fragment portion of legitimate URLs\u2014specifically, the text after the \u201c#\u201d symbol. When AI browsers process these URLs and users ask questions, the hidden instructions feed directly into the AI assistant\u2019s responses.<\/p>\n<p>Security researcher Vitaly Simonovich, who led the Cato Networks research, found that HashJack can manipulate Perplexity\u2019s Comet, Microsoft\u2019s Copilot for Edge, and Google\u2019s Gemini for Chrome. The attacks range from inserting fake callback numbers to exfiltrating user data in the background.<\/p>\n<p>\u201cHashJack is the first known indirect prompt injection that can weaponize any legitimate website to manipulate AI browser assistants,\u201d Simonovich said. \u201cBecause the malicious fragment is embedded in a real website\u2019s URL, users assume the content is safe while hidden instructions secretly manipulate the AI browser assistant.\u201d<\/p>\n<p>URL fragments never reach web servers or appear in network logs, making them invisible to traditional security tools. In Comet\u2019s case, the browser can automatically fetch attacker-controlled URLs with user data appended as parameters, sending account names, transaction history, and email addresses to external servers without user interaction.<\/p>\n<p>Microsoft and Perplexity responded to the HashJack disclosure with patches. Microsoft applied a fix to Copilot for Edge on October 27, and Perplexity patched Comet by November 18. <\/p>\n<p>Google classified the issue as \u201cwon\u2019t fix\u201d and assigned it low severity, according to Cato Networks\u2019 disclosure timeline. Google does not treat guardrail bypasses or policy-violating content generation as security vulnerabilities under its AI Vulnerability Reward Program, a company spokesperson confirmed.<\/p>\n<p>Both research findings underscore a broader risk. AI browser agents operate on trust: trust that emails are benign, trust that URLs are safe, trust that natural language instructions align with user intent. That trust becomes a vulnerability when attackers craft inputs designed to exploit how these systems interpret context.<\/p>\n<p>\u201cDon\u2019t just secure the model,\u201d Rousseau concluded in the Straiker blog. \u201cSecure the agent, its connectors, and the natural-language instructions it quietly obeys.\u201d<\/p>\n<p>As enterprises deploy AI copilots across email, cloud storage, and browsers, the lesson is urgent. Automation without guardrails can turn helpful assistants into silent saboteurs. <\/p>\n","protected":false},"excerpt":{"rendered":"A polite email asking an AI browser to \u201corganize your Drive\u201d can silently wipe your files. No phishing&hellip;\n","protected":false},"author":2,"featured_media":179723,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[97945,97940,97937,97943,97944,97939,97942,61,60,97938,30038,80,97941],"class_list":["post-179722","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ai-agent-manipulation","tag-ai-browser-assistants","tag-ai-browser-security","tag-ai-copilot-risks","tag-browser-automation-security","tag-google-drive-wiper-attack","tag-hashjack-vulnerability","tag-ie","tag-ireland","tag-perplexity-comet-vulnerability","tag-prompt-injection","tag-technology","tag-zero-click-attack"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/179722","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=179722"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/179722\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/179723"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=179722"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=179722"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=179722"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}