Single Browser Extension Can Seize AI Assistants in Five Chromium Products
Moyen · The Hacker News ·
En bref
- Forever Security demonstrated that one browser extension can access AI assistants in five Chromium-based products.
- Affected products named include Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension.
- The extension reportedly gained access with a single click after installation.
- No CVE was listed, and full technical details and vendor responses should be verified.
- Risk depends on what data and actions each built-in AI assistant can access.
Security researchers at Forever Security have demonstrated that a single browser extension can gain control of the built-in AI assistants in five Chromium-based products. The affected assistants named in the report are Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension. According to the available details, once the extension was installed it could access each product's AI with a single click. No CVE identifiers were listed, and the excerpt was truncated, so the full technical chain and any vendor responses still need verification.
Browser extensions are a familiar weak point because they often request broad permissions to read and change data on every site. When an AI assistant is embedded in the browser, that assistant may have access to page content, open tabs, account context, or the ability to take actions on a user's behalf. A malicious or compromised extension that can reach the assistant could therefore turn a trusted convenience feature into a data exposure or misuse path. The exact impact depends on what each assistant can see and do, which the report does not fully detail.
For K-12 and government users, the practical concern is not only the AI assistant itself but the extension supply chain. Shared devices, student accounts, and staff browsers often accumulate extensions that were never reviewed. If those extensions can silently interact with AI features, existing controls around web filtering and endpoint protection may not catch the behavior. This is a research demonstration, not evidence of active exploitation, so the immediate risk is moderate for most organizations.
IT teams should treat this as a prompt to tighten browser extension governance. That means knowing what is installed, limiting installs to approved extensions, and reviewing permissions that allow broad page or tab access. Where built-in AI assistants are not required, disabling or restricting them on managed devices reduces the attack surface. Watch for vendor advisories, updated extension policies, and any proof-of-concept details from Forever Security. Because no CVE is listed, patching alone may not be the right response; configuration and allowlisting are likely more important.
À faire maintenant
- Inventory browser extensions across managed Chrome, Edge, and other Chromium browsers, then remove unapproved or unknown extensions.
- Enforce extension allowlisting through enterprise browser policies and block user-installed extensions on shared or student devices.
- Review extensions with permissions to read or change all sites, access tabs, cookies, or debugging tools, and restrict or remove high-risk ones.
- Disable or limit built-in AI assistants on managed devices where they are not required for instruction or business tasks.
- Monitor for new extension installs and unusual AI assistant activity, and alert on high-risk permission changes.
- Apply browser and extension updates promptly, and track advisories from Forever Security and the affected vendors.
- Train staff and students to avoid installing unknown extensions and to report suspicious browser prompts or AI behavior.
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.