By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Single Extension Can Hijack AI Assistants in Major Browsers

Security researchers from Forever Security have identified a critical vulnerability where a single browser extension can compromise the AI assistants integrated into multiple Chromium-based browsers. This exploit affects Gemini Live within Google Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension. The researchers demonstrated that once this malicious extension is installed, it gains the ability to access and control each affected product's built-in AI with a single click. This level of access allows the extension to potentially perform actions on behalf of the user without their explicit consent or knowledge.
The vulnerability specifically targets the way these AI assistants are integrated into the browser environment. By exploiting common browser extension APIs and potentially manipulating inter-process communication mechanisms, the extension can inject commands or intercept data intended for the AI. This means that any AI assistant functionality that relies on accessing web content, user input, or browser APIs could be redirected or misused. For instance, an extension could instruct the AI to summarize sensitive web pages, draft emails using personal information, or even make purchases, all under the guise of legitimate user interaction.
Forever Security's findings highlight a significant security gap in the growing integration of AI into everyday browsing tools. As more AI assistants are embedded directly into browsers and applications, the attack surface for such vulnerabilities expands. The ease with which this single extension can gain control underscores the need for robust security vetting of browser extensions and for browser vendors to implement stricter sandboxing and permission models for AI integrations. The researchers have not yet disclosed the name of the specific extension or provided detailed technical specifications of the exploit, likely to prevent widespread immediate exploitation while mitigation strategies are developed.
The implications of this exploit are far-reaching. Users who have installed extensions from untrusted sources or extensions that have been compromised themselves could be at immediate risk. The ability for an extension to control an AI assistant means that sensitive user data, browsing history, and personal communications could be exposed or manipulated. This incident serves as a stark reminder for users to exercise caution when installing browser extensions and to regularly review the permissions granted to them. It also puts pressure on developers of AI-powered browser features to prioritize security and implement comprehensive safeguards against such sophisticated attacks.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.