Common Browser Extension Found Able to Seize Control of Multiple AI Chatbots
Security researchers at Forever Security have demonstrated that a seemingly ordinary browser extension can commandeer the AI chat assistants embedded in several popular Chromium-based browsers, raising fresh concerns about the safety of extensions that users routinely install.
The team showed that the extension, which requests typical permissions such as access to web page content and the ability to inject scripts, can intercept the communication between a user and the AI service. By modifying request parameters and response handling, the malicious code can redirect queries, alter answers, or even feed fabricated data back to the user, effectively taking over the assistant’s functionality without the user’s knowledge.
The vulnerability spans five distinct AI integrations: Gemini Live in Google Chrome, Perplexity’s Comet interface, Microsoft Edge’s built‑in assistant, Opera Neon’s AI feature, and Anthropic’s Claude when accessed through Chrome. All of these services rely on the same underlying Chromium framework, which the extension exploits to gain a foothold across the different products.
Embedding AI assistants directly into browsers has become a mainstream trend, with companies betting that on‑demand conversational tools will boost user engagement and productivity. As these assistants become more tightly coupled with the browsing experience, they also inherit the broader attack surface of the browser ecosystem, including third‑party extensions that often enjoy elevated privileges.
The researchers warn that an attacker who controls an AI assistant could harvest sensitive queries, inject misinformation, or even use the assistant as a conduit for phishing attempts. Because the extension operates at the browser level, its actions can be difficult for the AI service itself to detect, making the threat particularly insidious.
While no official comment has been issued by the affected browser vendors at the time of reporting, standard mitigation steps include tightening extension review processes, revoking unnecessary permissions, and prompting users to verify the legitimacy of extensions before installation. Security teams are likely to push updates that limit script injection capabilities or enforce stricter sandboxing for AI‑related APIs.
For everyday users, the immediate recommendation is to audit installed extensions, remove any that are unfamiliar or untrusted, and keep browsers up to date. Enabling built‑in protection features, such as Chrome’s extension safety checks or Edge’s SmartScreen, can provide an additional layer of defense while developers work to patch the underlying vulnerability.
Comments (0)
Be the first to comment.
Join the discussion