VMTech
Discuss a project

Browser Extensions Shown to Hijack AI Assistants Across Five Products

Browser Extensions Shown to Hijack AI Assistants Across Five Products

Researchers at Forever Security demonstrated that a single browser extension could hijack built-in AI assistants in Google Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and Claude in Chrome. The proof-of-concept attacks required the attacker’s extension to have already been installed, but could reach the targeted assistant with one click and, in several cases, cause an AI agent to act for the attacker.

The research was not evidence of in-the-wild exploitation. Its significance lies in the permissions involved: Forever Security said the extension needed two common capabilities, one for modifying web pages and declarativeNetRequest for changing browser network traffic. Those permissions are widely used by legitimate extensions, including ad blockers.

How the trusted-page boundary was bypassed

Browser AI products combine a local browser component, able to view pages, open files, use devices and take actions, with a server-side model that directs it. That local component is intended to accept instructions only from a trusted vendor page, such as Gemini’s site or Perplexity’s site. Forever Security’s method was to alter that trusted page through the extension and then send commands that appeared to originate with the vendor.

The effect differed by product. In Chrome, the demonstration could read local files, capture screenshots and enable the camera and microphone. In Comet, it could read local files, expose browser-profile and browsing-history data, take screenshots and control the agent. Edge, Opera Neon and Claude in Chrome were shown to permit AI-agent control, but not the additional file or device capabilities listed for Chrome and Comet.

Patch status varies by vendor

The Chrome issue, known as GlicJack, was first publicly detailed by Forever Security researcher Gal Weizman in March. It is tracked as CVE-2026-0628, carries a 8.8 severity rating from CISA, and Google fixed it in Chrome 143.0.7499.192. The finding also reinforces the browser-extension exposure described in browser-extension exposure in AI browsers as AI functions add another privileged surface inside familiar browser products.

Microsoft assigned CVE-2026-55945 to the Edge issue, rated 4.2, and fixed it in Edge 150.0.4078.48 on July 2. Forever Security said Edge required a more complex chain: takeover of a Microsoft marketing page permitted to send prompts to the assistant, followed by a race condition that switched the agent between its thinking and action modes.

Comet, Opera Neon and Claude in Chrome did not have CVEs for the methods described. Forever Security said Perplexity’s main page blocked extensions, but a test address, testing.perplexity.com, remained available for the technique. Opera Neon’s assistant accepted commands from opera.com, where extensions had not been blocked from running code. Anthropic rated the Claude in Chrome report medium severity and paid a bounty; Forever Security described it as the least serious case because one extension was abusing another extension rather than the browser.

Extension governance remains the practical control

Neither CVE was listed in CISA’s Known Exploited Vulnerabilities catalog as of September 16, 2026, and no public evidence showed real-world abuse of any of the five methods. Chrome and Edge users should install the cited fixed versions or later. Organisations using Comet, Opera Neon or Claude in Chrome should keep software current and review installed extensions, because the demonstrated chains all begin after a malicious extension gains a foothold in the browser.

#browsersecurity#aiextensions#vulnerability#extensionrisk
Open analytics
On the site 0 views
min read 4 16.09.2026
Instagram

Browser Extensions Shown to Hijack AI Assistants Across Five Products

Open the post on Instagram ↗