{*}
Add news
March 2010 April 2010 May 2010 June 2010 July 2010
August 2010
September 2010 October 2010 November 2010 December 2010 January 2011 February 2011 March 2011 April 2011 May 2011 June 2011 July 2011 August 2011 September 2011 October 2011 November 2011 December 2011 January 2012 February 2012 March 2012 April 2012 May 2012 June 2012 July 2012 August 2012 September 2012 October 2012 November 2012 December 2012 January 2013 February 2013 March 2013 April 2013 May 2013 June 2013 July 2013 August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 March 2014 April 2014 May 2014 June 2014 July 2014 August 2014 September 2014 October 2014 November 2014 December 2014 January 2015 February 2015 March 2015 April 2015 May 2015 June 2015 July 2015 August 2015 September 2015 October 2015 November 2015 December 2015 January 2016 February 2016 March 2016 April 2016 May 2016 June 2016 July 2016 August 2016 September 2016 October 2016 November 2016 December 2016 January 2017 February 2017 March 2017 April 2017 May 2017 June 2017 July 2017 August 2017 September 2017 October 2017 November 2017 December 2017 January 2018 February 2018 March 2018 April 2018 May 2018 June 2018 July 2018 August 2018 September 2018 October 2018 November 2018 December 2018 January 2019 February 2019 March 2019 April 2019 May 2019 June 2019 July 2019 August 2019 September 2019 October 2019 November 2019 December 2019 January 2020 February 2020 March 2020 April 2020 May 2020 June 2020 July 2020 August 2020 September 2020 October 2020 November 2020 December 2020 January 2021 February 2021 March 2021 April 2021 May 2021 June 2021 July 2021 August 2021 September 2021 October 2021 November 2021 December 2021 January 2022 February 2022 March 2022 April 2022 May 2022 June 2022 July 2022 August 2022 September 2022 October 2022 November 2022 December 2022 January 2023 February 2023 March 2023 April 2023 May 2023 June 2023 July 2023 August 2023 September 2023 October 2023 November 2023 December 2023 January 2024 February 2024 March 2024 April 2024 May 2024 June 2024 July 2024 August 2024 September 2024 October 2024 November 2024 December 2024 January 2025 February 2025 March 2025 April 2025 May 2025 June 2025 July 2025 August 2025 September 2025 October 2025 November 2025 December 2025 January 2026 February 2026 March 2026 April 2026 May 2026 June 2026 July 2026 August 2026 September 2026
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28
29
30
News Every Day |

Malicious browser extensions can hijack AI assistants

AI assistants are moving deeper into the browsers we use every day. They can summarize a webpage, explain what you are looking at and, in some cases, take action on websites for you. That convenience also gives these tools access that a normal webpage would never have. Now, security researcher Gal Weizman of Forever Security has shown how a malicious browser extension could potentially turn those powerful AI capabilities against you. His research, called BragJack, targeted Gemini Live in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon and Anthropic's Claude in Chrome. The findings resulted in more than $20,000 in bug bounties and two CVEs.

There is one important detail before you panic. The attack still required the malicious extension to be installed first. After that, Weizman demonstrated attacks that needed zero additional clicks from the victim. So how could one extension get that far inside the browser? It comes down to how these AI assistants are built.

Missed CyberGuy LIVE? Watch the replay and discover 5 ways AI can help you get better healthcare.

Our free CyberGuy LIVE class, Get Better Healthcare With AI, has ended, but you can still watch the full replay. Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed.

Watch the free replay + downloadable checklist now at CyberGuyLive.com.

AI MALWARE CAN REWRITE ITSELF TO EVADE DETECTION

Weizman describes these AI systems as having a "brain" and a "body." The AI model works out what should happen. A privileged component inside the browser then carries out the request. Depending on the product, that privileged component might read webpage content, capture a screenshot or interact with a website. That setup becomes risky if something else inside the browser can manipulate the connection between those pieces. The proof-of-concept attacks relied heavily on Chromium's declarativeNetRequest, or DNR, system. Browser extensions can use DNR to modify how network requests work. That can include changing response headers or redirecting resources. Forever Security showed how those capabilities could let an extension interfere with web content trusted by a browser's AI features.

Chrome was one of the more striking examples. Google's Gemini side panel essentially has two pieces. Gemini handles the intelligence behind the request while Chrome provides the browser-level abilities needed to carry it out. Researchers found that Chrome already prevented extensions from directly injecting scripts into the Gemini page. However, the researchers discovered that an extension could still manipulate certain network requests used inside the Gemini experience. That gap allowed Weizman to demonstrate access to browser capabilities that the extension itself should never have received. According to the research, he could access local files, capture screenshots and obtain browser profile information. The researcher says the flaw also let him turn on the camera and microphone with zero clicks from the user. Google awarded the researchers a $7,000 bounty for reporting the vulnerability, which received the identifier CVE-2026-0628.

Google has since confirmed to CyberGuy that it has closed this specific attack path. A Google spokesperson told us, "Confirming we've released a patch in Chrome so this method no longer works on the Gemini side panel." That means the technique demonstrated by the researchers should no longer work against the Gemini side panel in an updated version of Chrome.

Perplexity Comet raised a different concern because its AI agent can take actions inside websites. Weizman found that Comet's built-in agent trusted several Perplexity domains. One testing domain lacked the same extension protections used on the main Perplexity site. Normally, that testing address redirected elsewhere. The proof-of-concept used DNR to remove the redirect and load the page instead. That gave the extension a path to communicate with Comet's built-in agent. The demonstrated access included browsing history, screenshots and local files. Then things became more personal. Weizman demonstrated sending an instruction that told the agent to access Perplexity, summarize the victim's recent emails and send the information to another email address. The AI agent performed the browser actions using capabilities it already had.

Microsoft built safeguards into Edge to keep outside prompts from easily controlling what its AI agent could do. Researchers still found a way around them. Weizman discovered a timing flaw known as a race condition. In simple terms, his test extension could feed the AI a prompt and then quickly switch on its ability to take action before Edge finished checking whether the request should be allowed. That opened the door for the AI agent to carry out a command it should not have accepted. Microsoft tracked the flaw as CVE-2026-55945 and rated it medium severity. The company says Edge versions before 150.0.4078.48 were affected. Updating Edge closes this particular security hole.

Forever Security also demonstrated related attacks against Opera Neon and Claude in Chrome. There is an important difference with Claude. Claude in Chrome is itself a browser extension, rather than a complete browser. The researcher found that a page on Claude's domain could send prompts to the extension's side panel. Another extension could manipulate that trusted page and force prompts into Claude. Forever Security says Anthropic awarded a bounty for the finding and classified it as medium severity. Opera Neon also allowed the proof-of-concept extension to reach its AI agent. According to the researcher, that access could force the agent to carry out instructions on websites. All five demonstrations were Chromium-based, which helped the researcher reuse the same basic attack approach.

We reached out to Google, Microsoft, Perplexity, Opera and Anthropic for comment on the research. Google responded with the update included above. Microsoft pointed us to its CVE-2026-55945 security advisory and said it had nothing further to share. We did not hear back from Perplexity, Opera or Anthropic before our deadline.

LOCK DOWN YOUR CHATGPT ACCOUNT BEFORE THE NEXT AI ATTACK

You may already have heard about prompt injection. That usually involves hiding malicious instructions in something an AI reads. Weizman calls this new approach Prompt Forcing. Here, the attacker does not need to hide instructions inside a webpage and hope the AI follows them. The attacker can force a complete prompt into the agent through a channel that the browser or assistant trusts. The AI can then turn that plain-English instruction into legitimate browser actions. That creates an interesting problem for security software. A suspicious program stealing an email may be easier to spot. An approved AI agent opening a website and clicking a button can look like normal browser activity. The published BragJack research describes proof-of-concept attacks and does not report that these techniques have been exploited in the wild. Still, the research shows how the security equation changes as AI agents receive deeper access to browsers and computers.

The attack starts with something many of us barely think about anymore: a browser extension. CyberGuy has covered malicious extensions that pretended to be AI assistants, hijacked online accounts and even turned trusted extensions into data-stealing spyware. That makes extension cleanup one of the easiest steps you can take right now. Maybe you installed a coupon extension two years ago and forgot about it. Perhaps you tested an AI sidebar once and never opened it again. If you no longer need an extension, there is little reason to keep giving it access to your browser.

Browsers receive security fixes regularly, so install updates as soon as they become available. Google's response makes that especially relevant here. The company says it has already released the Chrome patch that blocks the Gemini side-panel method demonstrated by the researchers. Restart Chrome after an update if prompted so the newest version can finish installing.

Open your browser's extension manager and remove anything you do not recognize or no longer use. Here is the quickest way to check:

Chrome and Claude in Chrome: Click the three-dot menu → Extensions → Manage extensions → find the extension → Remove. Google confirms this path in its current Chrome instructions.

Microsoft Edge: Click the Extensions puzzle-piece icon → Manage extensions → find the extension → Remove.

Opera Neon: Open the Extensions area from the browser sidebar or menu → review your installed extensions → remove anything you no longer trust or use. Opera documents its extensions manager through the Extensions icon and menu.

Perplexity Comet: Open the browser's extensions manager and review imported or installed Chrome extensions. Comet supports Chrome extensions and can import them from Chrome.

Pro tip: If you are unsure about an extension, disable it first and research the developer before removing it.

THOUSANDS OF HACKED SITES TRICK YOU INTO INSTALLING MALWARE

Look carefully when an extension asks for broad access to websites or browser activity. The permission should make sense for what the extension actually does.

Some browsers let you decide whether an extension can run on every website or only certain sites. Give an extension the narrowest access it needs to work.

An extension that uses a familiar AI name may have no connection to the company behind that AI service. Check the publisher before installing it.

If your browser gives you the option to disable an AI assistant or agent you never use, consider turning it off. That reduces the number of powerful browser features available if another component gets compromised.

Strong antivirus software can help flag malicious downloads and suspicious activity connected to bad extensions. It adds another layer of protection if something slips past you. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com.

Do not install one because it sounds useful for five minutes. Every extension adds code and permissions to the browser you use for email, banking, shopping and other private activity.

What gets my attention here is how much more powerful a bad browser extension can become when an AI agent enters the picture. We already knew extensions could spy on browsing or steal account data. This research shows a possible path to something with much broader privileges. There is also a practical takeaway. These demonstrations still required the attacker-controlled extension to get inside the browser first. Once it was there, however, the researcher showed that the attack could continue without another click from the victim. I would take five minutes and look through your extensions today. If you cannot remember why you installed one, find out what it does. If you stopped using it months ago, remove it. As browser AI grows more capable, the companies building these tools also need strong barriers between ordinary extensions and the privileged systems that let AI act for us.

Would you still let an AI assistant control parts of your browser if a malicious extension could potentially turn that access against you? Let us know by writing to us at Cyberguy.com.

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.

Ria.city






Read also

Denver Broncos storm back from down 16-0 at halftime to beat Los Angeles Rams in instant classic

Christian McCaffrey sporting a busted lip after taking shot to face vs Cardinals

'Lover' Ashiq Ali arrested in Guwahati student Nimisha Thakuria death case

News, articles, comments, with a minute-by-minute update, now on Today24.pro

Today24.pro — latest news 24/7. You can add your news instantly now — here




Sports today


Новости тенниса


Спорт в России и мире


All sports news today





Sports in Russia today


Новости России


Russian.city



Губернаторы России









Путин в России и мире







Персональные новости
Russian.city





Friends of Today24

Музыкальные новости

Персональные новости