highOther

Cross-Browser AI Assistant Hijack via Malicious Extension

First seen Sep 17, 2026 · Updated Sep 17, 2026

agent-relevantbrowser-extensionai-assistantprivilege-escalationchromiumprompt-injection

Researchers at Forever Security demonstrated that a single malicious browser extension could hijack the built-in AI assistants across five Chromium-based browsers and their AI integrations: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge Copilot, Opera Neon, and the Claude in Chrome extension. Once installed, the extension gained one-click access to each product's embedded AI assistant, enabling unauthorized control or manipulation of assistant behavior across multiple vendor ecosystems simultaneously.

Technical Analysis

The attack exploits a shared architectural weakness in how Chromium-based browsers expose and authorize access to native AI assistant integrations, allowing an extension with standard permissions to interact with and potentially command multiple AI assistants without additional user consent per-product. This suggests insufficient isolation between browser extension APIs and AI assistant invocation surfaces, potentially enabling the extension to inject prompts, exfiltrate assistant context/conversation data, or trigger agentic actions (e.g., page automation, form-filling, purchases) that these assistants are authorized to perform on the user's behalf. No CVE has been publicly assigned at this time; the vulnerability appears to be a design-level flaw affecting the extension permission model rather than a memory-corruption bug. Because these AI assistants increasingly function as autonomous agents capable of taking actions within the browser (clicking, navigating, submitting data, invoking connected tools), a single compromised or malicious extension could hijack agentic capabilities across multiple AI products at once, turning trusted assistants into vectors for data exfiltration, unauthorized transactions, or lateral prompt injection attacks. This directly impacts organizations relying on browser-embedded AI agents for workflow automation, as the extension could manipulate agent behavior, exfiltrate sensitive session data, or misuse tool-calling permissions granted to the assistant.

Affected Systems

Google Chrome (Gemini Live integration), Perplexity Comet browser, Microsoft Edge (Copilot integration), Opera Neon, Claude in Chrome extension; all Chromium-based browsers with embedded AI assistant features are potentially at risk pending vendor confirmation and patching

Indicators of Compromise

  • No specific file hashes, IPs, or domains disclosed in source reporting; IOC details pending full technical disclosure from Forever Security

Remediation Steps

  1. 1

    Audit installed browser extensions

    Review and remove unnecessary or unverified browser extensions, especially those with broad permissions or access to AI assistant APIs.

  2. 2

    Restrict extension permissions

    Enforce enterprise policies limiting extension install sources to vetted, signed extensions from trusted publishers only (e.g., via Chrome Enterprise policy ExtensionInstallAllowlist).

  3. 3

    Monitor for vendor patches

    Track advisories from Google, Microsoft, Opera, Perplexity, and Anthropic for patches addressing AI assistant access control and apply updates immediately upon release.

  4. 4

    Limit AI assistant agentic permissions

    Where possible, disable or restrict AI assistant capabilities to perform autonomous actions (form submission, purchases, credential entry) until the isolation flaw is resolved.

  5. 5

    Deploy browser extension monitoring

    Use endpoint detection tools capable of flagging anomalous extension behavior, particularly unauthorized interaction with browser-native AI APIs.

Industries Most Exposed

technologysoftwarefinancial servicesprofessional servicesany enterprise using browser-embedded AI agents

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.