Comet is
Perplexity’s Chromium-based browser with an integrated AI assistant. It can browse ordinary websites, import familiar browser data, summarize and compare pages, use context from open tabs and perform supported actions on a user’s behalf.
It is available free on macOS, Windows, iOS and Android.
Comet’s main advantage is not an answer box beside a webpage. It is shared context: the assistant can understand what the user is viewing without a constant copy-and-paste loop. The same advantage explains its main risk. A browser sees accounts, forms, downloads, messages and potentially sensitive pages. Giving an AI assistant access to that context creates more consequence than asking a standalone search question.
The right way to evaluate Comet is therefore two-part:
- Does browser context save meaningful time?
- Can permissions and confirmations keep that context and action within an acceptable boundary?
This guide covers both. For Perplexity Search, Research, Projects and the wider product family, use the
Perplexity cornerstone.
Comet at a glance
TableCopy Table Raw
| Developer | Perplexity |
| Product type | Chromium-based web browser with AI assistance and agentic actions |
| Platforms | macOS, Windows, iOS and Android |
| Price | Free browser; some assistant capabilities depend on the Perplexity plan |
| Browser compatibility | Built on Chromium, with familiar extension and website compatibility |
| Core assistant uses | Page summaries, tab comparison, contextual questions, extraction and supported actions |
| Local password storage | Operating-system vault: Keychain on macOS, Credential Manager on Windows |
| Enterprise version | Yes, with administrative policies and controls |
| Main benefit | AI can work in the browsing context |
| Main risk | Page content and broad permissions can influence an agent with access to accounts |
| Official page | perplexity.ai/comet |
What makes Comet different from adding a chatbot extension?
A typical browser extension operates inside another company’s browser and receives only the permissions declared by the extension. Comet is the browser. Perplexity can design navigation, search, side-panel assistance, history, tab context and agent actions as one product.
That integration can reduce friction:
- ask a question about the current page;
- compare several tabs without copying their contents;
- find the relevant paragraph in a long document;
- turn a browsing session into a summary;
- fill or navigate supported forms;
- draft a message from material on screen;
- and continue Perplexity research without leaving the browser.
It also expands the trust boundary. The browser processes credentials, cookies, signed-in sessions and everything rendered by a page. A responsible user should not give its AI component universal access merely because the browser itself needs broad technical access.
How to install and set up Comet
1. Download from the official source
Use
Perplexity’s Comet page or the official Apple or Google store listing. Avoid third-party download pages and sponsored lookalikes.
2. Import only what you need
Comet can import browser material such as:
- bookmarks;
- browsing history;
- saved passwords;
- autofill information;
- and extensions, where supported.
A full import is convenient but not mandatory. A cautious first test can begin with bookmarks only, leaving passwords and payment autofill in the existing browser.
3. Understand the keychain request
On installation, Comet may request access to the operating system’s secure credential storage. Perplexity says this is used for data such as website credentials, payment autofill, authentication tokens and encrypted information used by intelligence features.
On macOS, passwords are kept in Keychain. On Windows, Comet uses Credential Manager. The operating system can require local verification before autofill.
4. Review sync
Most ordinary browsing information is stored locally unless the user explicitly enables synchronization with a Perplexity account. Decide which device settings, bookmarks or browsing data should sync before turning it on.
5. Set assistant permissions
Do not approve every capability during onboarding. Start with page reading and low-risk navigation. Add access to sites or accounts only when a repeatable task needs it.
6. Keep a fallback browser
During evaluation, retain a familiar browser for banking, administration, password changes and other sensitive tasks. This makes gradual adoption easy and reduces pressure to grant Comet every permission immediately.
What Comet stores on the device
Perplexity’s
local storage documentation says most browsing data remains on the device, including:
- browsing and search history;
- cookies and site data;
- cached files;
- autofill form data;
- and the download-history list.
Saved passwords are encrypted in the operating system’s vault. Downloaded files remain on disk even after browsing data is cleared. Synced settings live separately in the Perplexity account.
This creates an important deletion rule:
Clearing local Comet browsing data does not necessarily delete synced Perplexity settings, account history, downloaded files or content stored in another connected service.
Deletion needs to follow the data to each location.
Incognito mode: what it does and does not do
When an Incognito window closes, Comet says it does not retain that window’s browsing history, cookies, form fills or passwords locally.
Incognito does not make activity invisible to:
- the websites visited;
- an employer or school network;
- the internet service provider;
- downloaded files;
- bookmarks created;
- or permissions changed.
If the user invokes Comet AI in Incognito, the query and context required to answer it are still sent to Perplexity’s servers. Perplexity says those AI interactions are not saved to account history when AI Data Retention is off, while
security and abuse-prevention logs can still exist.
Incognito is a local-history control, not anonymity and not a no-processing mode.
What can the Comet Assistant do?
Capabilities vary by platform, plan, site and rollout. Common categories include:
Understand a page
Ask for:
- the central argument;
- a definition in context;
- a list of dates or people;
- the difference between two sections;
- or an explanation for a specific audience.
For consequential claims, open the source passage instead of relying on the summary.
Work across tabs
Comet can compare products, policies, itineraries or other material across several open pages. Give explicit dimensions:
Compare the four open plan pages on monthly price, annual price, data treatment, seat minimum and cancellation. Use only text visible in those pages. Mark missing information instead of inferring it.
Navigate and extract
The assistant can help locate a control, follow a series of pages or turn unstructured material into a table. This is useful for discovery; validate extracted numbers.
Perform actions
With suitable permission, an agent can interact with sites and logged-in services. Examples can include drafting or sending a message, filling a form, organizing information or assisting with shopping.
Action is where human confirmation becomes essential.
A safe permission model
Use three tiers.
Tier 1: read-only and public
Good starting tasks:
- summarize public pages;
- compare open documentation;
- extract a public table;
- navigate an unfamiliar website;
- draft text without sending it.
Tier 2: private but reversible
Require inspection:
- read selected email or calendar information;
- prepare a draft in a signed-in service;
- organize a non-sensitive workspace;
- add items to a cart without ordering;
- fill a form without submission.
Tier 3: consequential or hard to reverse
Keep a human at the final step:
- sending messages;
- making purchases;
- publishing;
- deleting data;
- changing account permissions;
- accepting legal terms;
- handling banking;
- resetting passwords;
- disclosing health, employment or identity information.
An agent’s ability to click a button is not a reason to remove approval.
Prompt injection in an AI browser
Prompt injection occurs when untrusted page content contains instructions intended to manipulate the assistant. The malicious text can be visible, hidden or embedded in content the agent reads.
An attack might try to persuade an assistant to:
- ignore the user’s instruction;
- reveal information from another tab;
- send data to an attacker;
- download or execute something;
- or approve a transaction.
Traditional browsers render hostile content but do not usually treat it as an instruction. An AI browser must distinguish webpage data from authorized user commands.
Reduce prompt-injection risk
- Keep the agent on the minimum number of tabs.
- Close sensitive pages before exploring an untrusted site.
- Deny a page access to unrelated account context.
- Require confirmation for external communication and transactions.
- Read the proposed action, recipient, amount and destination.
- Do not allow a page to redefine the task.
- Stop when the agent requests an unexpected permission.
- Use an isolated browser profile for higher-risk research.
Independent security findings
Security research is useful only when the status of a finding is clear.
Guardio’s Scamlexity tests
Guardio Labs tested agentic browsers against scam and malicious-page scenarios in 2025. The work illustrated a category-level problem: an agent can interact with deceptive content more actively than a passive browser.
The tests do not prove that every current Comet session will fail. They support the need for constrained permissions and transaction approval.
Zenity’s PleaseFix and PerplexedAgent research
Zenity Labs disclosed a chain that could expose local data through the browser agent. The researchers say they responsibly disclosed it in October 2025. Perplexity implemented a stronger trust boundary, and Zenity confirmed on February 13, 2026 that the reported attack no longer worked.
It should be described as a fixed historical vulnerability, not a known unpatched flaw.
The episode still teaches an architectural lesson: browser agents need explicit separation between untrusted web instructions and trusted local resources.
Comet and the Amazon dispute
Amazon sued Perplexity over an agent that could access Amazon customer accounts and place orders. Amazon alleged unauthorized automated access and disguising agent traffic as human browsing. Perplexity disputed the case and framed it as a question of user choice.
A federal judge issued a preliminary restriction in March 2026; an appeals court temporarily paused that order, and the Ninth Circuit
heard arguments in June. At the time of review, the dispute was ongoing.
The case is not proof that every Comet use is unlawful. It exposes a new question: when an agent uses a signed-in account, who is technically and legally accessing the service, and which site rules apply?
Users should not assume that authorizing an agent overrides a website’s terms or technical restrictions.
Comet for Enterprise
Perplexity offers an enterprise version with administrator controls and deployable browser policies.
Published controls include areas such as:
- sign-in restrictions;
- synchronization;
- extension management;
- password and autofill behavior;
- site permissions;
- security settings;
- and other Chromium-derived policies.
Administrators should treat Comet as both a browser deployment and an AI deployment. The rollout needs:
- managed versions and updates;
- allowed extensions;
- identity and device policy;
- AI data settings;
- approved use cases;
- sensitive-site rules;
- incident handling;
- and agent-action controls.
The
Perplexity Enterprise guide covers the larger organizational system.
Ten useful Comet workflows
1. Compare current documentation
Open only the relevant official pages. Ask for a matrix of named fields, with “not stated” for missing data.
2. Summarize a long page
Ask for claims, evidence, exceptions and dates rather than a generic summary.
3. Inspect a terms change
Open old and new versions where available. Ask Comet to identify changed clauses, then verify line by line.
4. Research before writing an email
Let the assistant create a draft from selected public tabs. Review it before granting access to the mail account.
5. Build a reading list
Ask for the original sources cited by several secondary pages, remove duplicates and open the most authoritative items.
6. Extract event details
From the event page, extract location, time zone, price, cancellation terms and accessibility information. Confirm before booking.
7. Compare shopping options
Ask for total price, shipping, return policy and vendor. Add to cart if useful, but place the order manually.
8. Navigate a complex government site
Use the assistant to locate the form or guidance. Verify the domain and complete submission yourself.
9. Review open support tickets
In an approved work profile, summarize themes without sending replies. Remove unnecessary customer identifiers from the output.
10. Turn tabs into a research note
Ask for a sourced note containing only the open pages, then move the verified result into the approved knowledge system.
When not to use the Comet Assistant
Keep the assistant out of:
- a password manager’s master interface;
- online banking;
- tax filing;
- administrative identity controls;
- confidential legal or medical systems without explicit approval;
- destructive production controls;
- or any page where the data class exceeds the account and company policy.
Ordinary manual browsing in Comet can still be possible. The issue is granting AI access to page context and actions.
Comet versus Chrome, Edge and Safari
Comet’s differentiator is integrated Perplexity assistance. Chrome, Edge and Safari have larger platform ecosystems, long-established enterprise deployment and their own evolving AI features.
Choose Comet when contextual AI creates a clear advantage and its policies meet the use case. Stay with the incumbent browser when compatibility, enterprise management, existing security tooling or a lower AI trust surface matters more.
Using two browsers is a valid arrangement: Comet for public research, a managed incumbent for sensitive accounts.
Frequently asked questions
Is Comet browser free?
Yes. Perplexity offers the browser free, while some assistant capacity and premium Perplexity features depend on the subscription.
Is Comet based on Chrome?
It is based on Chromium, the open-source browser project that also underpins Chrome and several other browsers. It is not Google Chrome.
Can Comet use Chrome extensions?
Chromium compatibility supports many familiar extensions, subject to platform and extension behavior. Review every extension’s permissions.
Where does Comet store passwords?
Perplexity says saved passwords are encrypted in the operating system’s secure vault: Keychain on macOS and Credential Manager on Windows.
Does Comet upload all browsing history?
Perplexity says most browsing information stays locally unless the user enables synchronization. Invoking AI features sends the query and necessary context to Perplexity for processing.
Is Incognito private from Perplexity?
Incognito prevents several local records from persisting after the window closes. AI requests still require server processing, and security logs can remain.
Is Comet safe?
It can be used safely for many tasks when kept updated and given limited permissions. Agentic browsing adds risks such as prompt injection and unintended action, so sensitive steps need human control.
Was the Zenity vulnerability fixed?
Zenity says Perplexity implemented a fix and the disclosed attack no longer worked when retested in February 2026.
Can Comet buy things for me?
Supported agents can assist with shopping in some contexts. Review the product, seller, price, address and terms, and keep final purchase confirmation manual.
Can a company manage Comet?
Yes. Comet for Enterprise supports administrative policies. Organizations still need use-case governance and incident procedures.
The bottom line
Comet makes AI assistance feel native to browsing. For public research, page comparison and navigation, that can be substantially more efficient than moving material into a separate chat window.
The browser is also where an AI assistant can encounter hostile content and sensitive accounts at the same time. The solution is not to treat every agent feature as unsafe or every prompt as trusted. Start read-only, isolate sensitive work, grant permissions narrowly and confirm every consequential action.
Comet is most useful when it reduces browser friction without removing the user’s control of the browser.