Perplexity’s BrowseSafe tries to patch the gaping security holes inherent in AI browser agents

Perplexity’s BrowseSafe tries to patch the gaping security holes inherent in AI browser agents

By Jonathan Kemper
Publication Date: 2025-12-07 09:23:00



Summary

Perplexity has developed a security system designed to protect AI browser agents from manipulated web content. According to the company, the system—called BrowseSafe—achieves a detection rate of 91 percent for prompt injection attacks.

This performance is higher than existing solutions. For example, smaller models like PromptGuard-2 detect 35 percent of attacks, while large frontier models like GPT-5 reach 85 percent. BrowseSafe also runs fast enough for real-time use, according to Perplexity.

Scatter plot shows F1 score versus latency of different AI models. BrowseSafe leads with over 90 percent F1 score at under 0.5 seconds. Frontier models with reasoning achieve 85-87 percent, but require 2-20 seconds. Smaller models range from 73-88 percent and 0.5-5 seconds latency.
BrowseSafe leading the pack with over 90 percent accuracy and minimal lag. While frontier models like Sonnet 4.5 offer similar precision, they require more than 20 seconds per check. | Image: Perplexity

Browser agents create new vulnerabilities

Earlier this year, Perplexity launched Comet, a web browser featuring integrated AI agents. These agents can view websites just as users do, performing actions in authenticated sessions for services like email, banking, and enterprise applications.

This level…