{"id":178302,"date":"2025-10-06T16:55:34","date_gmt":"2025-10-06T15:55:34","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/es\/?p=397992"},"modified":"2025-10-06T16:56:14","modified_gmt":"2025-10-06T15:56:14","slug":"ceci-est-le-cometjacking-une-nouvelle-facon-de-te-voler-toutes-tes-donnees","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/fr\/ceci-est-le-cometjacking-une-nouvelle-facon-de-te-voler-toutes-tes-donnees\/","title":{"rendered":"Ceci est le CometJacking : une nouvelle fa\u00e7on de te voler toutes tes donn\u00e9es"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Des chercheurs en cybers\u00e9curit\u00e9 ont r\u00e9v\u00e9l\u00e9 une nouvelle attaque appel\u00e9e CometJacking, ciblant le navigateur Comet de Perplexity. <strong>Cette attaque repose sur l&#8217;injection de prompts malveillants dans des liens apparemment inoffensifs, permettant de voler des donn\u00e9es sensibles de services connect\u00e9s comme Gmail et Calendrier<\/strong>. La menace s&#8217;active en cliquant sur un lien con\u00e7u, ce qui provoque l&#8217;ex\u00e9cution d&#8217;un prompt cach\u00e9 par le navigateur, capturant des informations personnelles et les envoyant \u00e0 un serveur contr\u00f4l\u00e9 par l&#8217;attaquant.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Un probl\u00e8me de s\u00e9curit\u00e9 tr\u00e8s grave<\/h2>\n\n\n<p class=\"wp-block-paragraph\">L&#8217;enqu\u00eate a mis en \u00e9vidence comment un seul lien pi\u00e9g\u00e9 peut transformer un navigateur AI, <strong>consid\u00e9r\u00e9 comme un assistant fiable, en une menace interne. Michelle Levy, responsable de la recherche en s\u00e9curit\u00e9 chez LayerX, a indiqu\u00e9 que \u00ab il ne s&#8217;agit pas seulement de voler des donn\u00e9es ; il s&#8217;agit de d\u00e9tourner l&#8217;agent qui a d\u00e9j\u00e0 les cl\u00e9s \u00bb<\/strong>. Ce type d&#8217;attaque contourne les mesures de protection des donn\u00e9es de Perplexity en utilisant des astuces simples d&#8217;obfuscation comme le codage Base64.<\/p>\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"AI Browser Allows Data Theft\" width=\"840\" height=\"473\" src=\"https:\/\/www.youtube.com\/embed\/y2S1_DtrUWU?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n<p class=\"wp-block-paragraph\">L&#8217;attaque CometJacking op\u00e8re en cinq \u00e9tapes : elle s&#8217;active lorsqu&#8217;une victime clique sur un lien malveillant, que ce soit dans un e-mail de phishing ou sur une page web. <strong>Au lieu de diriger l&#8217;utilisateur vers la destination pr\u00e9vue, le lien demande \u00e0 l&#8217;intelligence artificielle du navigateur Comet d&#8217;ex\u00e9cuter un prompt cach\u00e9 qui capture les donn\u00e9es de l&#8217;utilisateur et les envoie \u00e0 un point final contr\u00f4l\u00e9 par l&#8217;attaquant<\/strong>.<\/p>\n\n\n<p class=\"wp-block-paragraph\">Bien que Perplexity ait class\u00e9 les d\u00e9couvertes comme n&#8217;ayant \u00ab aucun impact sur la s\u00e9curit\u00e9 \u00bb, la situation met en lumi\u00e8re les vuln\u00e9rabilit\u00e9s inh\u00e9rentes aux outils natifs d&#8217;intelligence artificielle. <strong>Les organisations doivent revoir et am\u00e9liorer les contr\u00f4les pour d\u00e9tecter et neutraliser ces prompts malveillants, car les attaques peuvent se transformer en campagnes g\u00e9n\u00e9ralis\u00e9es, transformant les navigateurs en points de contr\u00f4le \u00e0 l&#8217;int\u00e9rieur des r\u00e9seaux d&#8217;entreprise<\/strong>.<\/p>\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/2d9f9134-96d0-11e6-bf8f-00163ec9f5fa\/1408299994\/avast-Avast_Symbol_V2_Positive_Orange_256x256.png\" alt=\"Avast Antivirus Gratuit\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Avast Antivirus Gratuit<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/avast.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">T\u00c9L\u00c9CHARGER<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        \r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/avast.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Des chercheurs en cybers\u00e9curit\u00e9 ont r\u00e9v\u00e9l\u00e9 une nouvelle attaque appel\u00e9e CometJacking, ciblant le navigateur Comet de Perplexity. Cette attaque repose sur l&#8217;injection de prompts malveillants dans des liens apparemment inoffensifs, permettant de voler des donn\u00e9es sensibles de services connect\u00e9s tels que Gmail et Calendrier. La menace s&#8217;active en cliquant sur un lien con\u00e7u, ce qui provoque l&#8217;ex\u00e9cution d&#8217;un prompt cach\u00e9 par le navigateur, capturant des informations personnelles et les envoyant \u00e0 un serveur contr\u00f4l\u00e9 par l&#8217;attaquant. Un probl\u00e8me de s\u00e9curit\u00e9 tr\u00e8s grave La recherche a mis en \u00e9vidence comment un seul lien empoisonn\u00e9 peut transformer un navigateur AI, qui se [&hellip;]<\/p>\n","protected":false},"author":9318,"featured_media":178303,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[16761,22339],"tags":[17677,28163,28164,691,13508,25167,4399],"usertag":[],"vertical":[],"content-category":[17507,18042],"class_list":["post-178302","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-softwaresecurity","tag-ciberseguridad","tag-comet","tag-cometjacking","tag-hacking","tag-ia","tag-perplexity","tag-phising","content-category-ia","content-category-seguridad-privacidad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/posts\/178302","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/users\/9318"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/comments?post=178302"}],"version-history":[{"count":2,"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/posts\/178302\/revisions"}],"predecessor-version":[{"id":178309,"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/posts\/178302\/revisions\/178309"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/media\/178303"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/media?parent=178302"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/categories?post=178302"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/tags?post=178302"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/usertag?post=178302"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/vertical?post=178302"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/fr\/wp-json\/wp\/v2\/content-category?post=178302"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}