Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

Browser Extensions Found Hijacking AI Assistants Across Major Chromium Platforms

Cahyo Dewo, September 17, 2026

Security researchers at Forever Security have unveiled a sophisticated vulnerability that exposes the inherent risks of integrating AI assistants directly into browser environments. The investigation, which spanned five prominent Chromium-based products—Google Chrome’s Gemini Live, Perplexity’s Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension—demonstrates that a standard, low-privilege browser extension can be weaponized to seize control of high-level AI agents. By exploiting trust-based communication channels between browser interfaces and server-side AI "brains," researchers proved that attackers could potentially execute commands, exfiltrate sensitive user data, and even manipulate hardware peripherals like cameras and microphones without explicit user intervention.

The Anatomy of the Exploit: Bridging the Security Gap

Modern AI-integrated browsers utilize a "body and brain" architecture. The "body" resides locally within the browser, functioning as an interface capable of interacting with the user’s file system, screen, and hardware. The "brain," meanwhile, operates on the vendor’s servers, processing requests and sending instructions back to the local body.

The security flaw identified by Forever Security hinges on the way these browsers establish trust. These agents typically listen for instructions only from specific, whitelisted web pages. However, researchers discovered that by leveraging two common, legitimate browser permissions—the ability to modify web page content and the power to manipulate network traffic via the declarativeNetRequest API—a malicious extension can effectively "spoof" its way onto these trusted pages. Once the extension successfully masquerades as the legitimate vendor page, it can issue arbitrary commands to the AI agent, which the agent executes under the assumption that it is communicating with its developer.

Chronology of Discovery and Disclosure

The trajectory of this research began in early 2026, marking a significant shift in how security professionals view AI-driven browser features.

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
  • March 2026: Researcher Gal Weizman of Forever Security publicly disclosed "GlicJack," a vulnerability affecting Google Chrome. This initial discovery highlighted the potential for malicious extensions to hijack the Gemini Live interface.
  • January 2026 (Fix): Google deployed a patch in Chrome version 143.0.7499.192, addressing the vulnerability now tracked as CVE-2026-0628. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) assigned it a severity score of 8.8, reflecting its potential impact on user privacy.
  • April 2026: Security firm LayerX identified a related vulnerability, dubbed "ClaudeBleed," within the Claude in Chrome extension, signaling that the issue was not isolated to one vendor.
  • July 2, 2026: Microsoft issued a fix for Edge in version 150.0.4078.48, addressing a more complex, multi-stage exploit tracked as CVE-2026-55945, which required researchers to bypass security measures using a combination of a marketing page takeover and a "race condition" attack.
  • July 2026: Manifold Security reported that residual gaps remained in the Claude extension, despite earlier efforts to secure the platform.
  • September 2026: Forever Security finalized its comprehensive report on the five platforms, resulting in approximately $20,500 in total bounty payouts across the affected vendors.

Comparative Vulnerability Matrix

The severity and capability of these exploits varied significantly depending on the architectural design of each browser. Perplexity’s Comet browser emerged as the most critical case due to its nature as a purpose-built AI environment. Because Comet provides its AI with broad system-level permissions, a successful hijack allowed researchers to read local files, scrape browsing history, capture screenshots, and assume the user’s digital identity.

In contrast, the "Claude in Chrome" extension was categorized as a lower-risk finding. Because it is an extension rather than a full browser, the attack was classified as an "extension-on-extension" exploit, which limits the potential damage compared to a full browser-level compromise. Microsoft Edge proved the most resilient, requiring researchers to chain multiple vulnerabilities—specifically exploiting a marketing page and a timing-based race condition—to gain control.

Industry Response and Official Remediation

The response from the tech industry highlights the ongoing tension between rapid AI deployment and secure development lifecycles. Following the disclosures, companies moved to implement stricter sandboxing and origin-validation checks.

Google and Microsoft have successfully deployed patches for their respective CVEs. However, the status of Comet, Opera Neon, and the Claude extension remains more ambiguous. While all vendors involved provided bug bounty payments to Forever Security, not all have publicly committed to specific patch timelines for the exact methods described.

Anthropic, the developer of Claude, acknowledged the findings and credited the researchers for their early disclosure, though the company’s internal teams had already been monitoring similar reports. Perplexity has taken steps to further isolate its AI-testing environments, specifically locking down subdomains that were previously susceptible to the "testing" loophole exploited by researchers.

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

Implications for Future AI Development

The findings from Forever Security serve as a cautionary tale for the integration of generative AI into web browsers. By moving the "brain" of the AI to the cloud and the "body" to the local machine, developers have created a persistent, high-privilege bridge that bypasses traditional browser security models.

Historically, browser extensions were prevented from accessing sensitive hardware or deep file systems through strict permission sets. However, when an AI agent is granted these powers, the browser essentially hands the keys to its most sensitive functions to an entity that—if compromised—can be tricked into executing malicious code.

Security experts emphasize that the threat is currently theoretical in the sense that no mass-market campaigns have been observed utilizing these specific methods. Nevertheless, the attack vector is well-understood: it relies on the user installing a malicious extension, a common technique in modern cybercrime. As AI-integrated browsers move from experimental features to default daily tools, the risk of "prompt injection" and "agent hijacking" will likely become a primary focus for security researchers.

Defensive Best Practices for Users

For the average user, the implications are clear: the privilege granted to browser extensions is now a high-stakes security consideration. To mitigate these risks, industry experts recommend the following:

  1. Strict Extension Auditing: Users should periodically review their browser extensions and remove any that are not essential or that originate from unverified developers.
  2. Regular Software Updates: As seen with the Chrome and Edge patches, keeping browser software current is the primary defense against documented CVEs.
  3. Permissions Vigilance: While standard users cannot easily "audit" the code of an extension, they should be wary of extensions requesting excessive permissions, such as "access to all web pages" or "management of network traffic."
  4. Hardware Awareness: Users should utilize privacy covers for webcams and be aware that, in the event of a browser compromise, peripherals are no longer inherently secure.

The research conducted by Forever Security underscores a critical reality: the evolution of the web into an AI-augmented environment requires a parallel evolution in browser security architecture. As browsers continue to integrate sophisticated AI agents, the industry must transition toward a "zero-trust" model for AI interactions, ensuring that even if an extension manages to breach the browser’s surface, it cannot command the AI agent to act against the user’s interests. Until such architectures are standardized, the responsibility for securing these complex systems remains a shared burden between developers, who must build stronger safeguards, and users, who must exercise increased caution in their digital environments.

Cybersecurity & Digital Privacy acrossassistantsbrowserchromiumCybercrimeextensionsfoundHackinghijackingmajorplatformsPrivacySecurity

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes