Browser Extension Reportedly Hijacks AI Assistants in Five Chromium Products

Medium · The Hacker News ·

Verification: The claim is a research demonstration without CVE IDs or vendor confirmation, and the article URL is dated in the future, so it cannot be verified as a real security event.

Key points

  • A demonstration extension reportedly gained control of AI assistants in five Chromium-based tools.
  • Named products include Chrome's Gemini Live, Microsoft Edge, Opera Neon, Perplexity Comet, and the Claude extension for Chrome.
  • No CVE, affected versions, actor attribution, vendor response, or official mitigations were provided.
  • The cited publication date appears later than May 2026, so details should be treated cautiously.

A newly described proof-of-concept raises concerns about how browser extensions interact with built-in AI helpers. According to a report, researchers at Forever Security demonstrated an add-on that, once installed, could reach each product's integrated assistant with a lone click. The products named are Chrome's Gemini Live, Microsoft Edge, Opera Neon, Perplexity Comet, and the Claude extension for Chrome.

Affected users are those running those Chromium-based browsers or extensions and using their AI features. Because extension permissions are often granted broadly at install time, an add-on may inherit access to page content, browser APIs, or assistant context without further prompts. That creates a path where a malicious or compromised extension could read prompts, alter responses, or issue actions through the AI assistant.

Why it matters: browser AI assistants increasingly handle sensitive workflows, including email drafting, web navigation, and internal search. If an extension can silently take over that channel, it can bypass normal user intent and blur the line between helpful automation and unauthorized control. The risk is amplified in K-12 and government environments where browser profiles may access student records, email, and administrative systems.

Context remains thin. The excerpt provides no CVE identifiers, affected versions, threat actor attribution, vendor statements, or mitigation guidance. It also cites a publication date ahead of May 9, 2026, which suggests the report may be future-dated or unreliable; analysts should verify primary sources before acting.

What to watch: vendor advisories, extension store removals, browser policy updates, and any signs of unauthorized AI prompts or data exfiltration. Until then, treat unknown extensions as untrusted and review which add-ons can interact with AI features.

What to do now

  1. Immediately inventory installed extensions in Chrome, Edge, Opera, and any Chromium-based browsers; remove or disable anything not explicitly approved.
  2. Enforce an extension allowlist through browser management policies and block user-installed or sideloaded add-ons.
  3. Review AI assistant settings and permissions; disable built-in AI features where they are not required for business or classroom tasks.
  4. Monitor for unexpected prompts, assistant actions, or outbound traffic from browser processes, and alert on new extension installs.
  5. Run high-risk browsing and AI use in isolated profiles or containers with no access to SSO, email, or student data.
  6. Brief staff and students not to install unapproved extensions and to report unexpected AI behavior.
  7. Track vendor advisories and extension-store removals; apply browser updates as soon as fixes are available.

Original source

The Hacker News

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news