These days, all the major browsers want to fit an AI assistant into a corner of your screen; however, a team at Forever Security has shown this may not be as advantageous as it seems.

In a recent article, researcher Gal Weizman explained that a simple browser extension can take control of the built-in AI in five different browsers, including Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Anthropic’s Claude in Chrome.

The researchers say the same extension worked against all of them, and in some cases the victim didn’t even have to click anything.

After it had been installed, the extension was able to do much more than just display a web page. In Chrome, it could open your files, take screenshots, retrieve your browsing history, and even turn on your camera and microphone without the normal permission pop-up appearing.

As the team put it, the attack “might have enabled the attacker to carry out a hidden recording of the victim without triggering the consent box.” That’s the point that should make anyone pause and think.

The entire system functions by undermining the security settings that a browser normally relies on, a scenario not too different from one we discussed previously. In that case, researchers found 19 extensions that bypassed browser security to steal passwords.

What makes this case different is that the AI itself is used as the tool. Instead of writing complex code to search your inbox, the attacker can just tell the assistant what to do in plain English. For example, one prompt in the report asks the agent to summarize the last five emails and quietly send them to an external address.

You do not have to download anything suspicious for this to happen. Extensions can show up in unexpected ways, and we recently even reported how malware forced rogue extensions to install on both Chrome and Edge without consent.

That said, browser companies are making an effort. For example, Microsoft is using automation to speed up its review of Edge extensions, and Google has finally discontinued older Manifest V2 extensions, at least in part, for reasons like this.

Forever Security has earned about $20,000 from bug bounties and has received two official CVEs as a result of the flaws, and the companies concerned have patched them.

ai-browsers-hijacked-with-extension

Yet the lesson is well known. When checking your extensions, remove any you don’t use, and stay cautious about free offerings, as even fake “free VPN” extensions have been found to steal clipboard contents.

We stand out from the tech-media crowd because we break news stories; we mainly bring you stuff that you won’t find anywhere in the mainstream tech media. Our stories have been picked up by some of the world’s most popular websites and media outlets—more info is available here.

Dwayne Cubbins
3036 Posts

I cover fast-moving stories across apps, online platforms, and everyday tech — phones, wearables, consoles, and whatever else people are fighting with this week. Bugs, rollouts, scams, policy enforcement, and the occasional internet-culture rabbit hole are all fair game. My goal is simple — make confusing tech news readable. When I'm not working, I'm working out or chilling with my dog. Got a tip? You can find me on X @dcubbins.