news.mlab.sh
Back to the feed
vulnerability

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

HighCVSS 8.8
Summary

Security researchers at Forever Security discovered a vulnerability that allows a single browser extension to hijack AI assistants built into five Chromium-based products: Chrome, Comet, Edge, Opera Neon, and Claude in Chrome. The extension can gain significant control over the AI, including accessing files, taking screenshots, and acting on behalf of the user. While Google and Microsoft have patched the issue in Chrome and Edge, Comet, Opera Neon, and Claude in Chrome remain vulnerable until updates are applied. The vulnerability stems from a low-privilege extension gaining access to a high-privilege part of the browser, a common issue with AI-driven browsers.

Security researchers at Forever Security have uncovered a critical vulnerability that enables a single browser extension to take control of the AI assistants integrated into five Chromium-based products: Google Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome. The vulnerability allows an attacker to hijack these AI assistants, granting them significant control over the user’s browser and computer.

Once the malicious extension is installed, it can access the AI agent’s “body,” which has broad capabilities within the browser, including the ability to read any file on the user’s computer, list the websites they’ve visited, and take screenshots. It can also act on behalf of the user, effectively mimicking their actions. The core issue lies in the fact that these AI assistants operate within a browser, and a low-privilege extension can exploit a weakness to gain access to a high-privilege area of the browser.

Google fixed the vulnerability in Chrome version 143.0.7499.192 and Edge version 150.0.4078.48 on January 2026. Microsoft also addressed the vulnerability in Edge version 150.0.4078.48 on July 2, 2026. However, Comet, Opera Neon, and Claude in Chrome remain vulnerable, as their vendors have not yet released patches.

Forever Security discovered the flaw by exploiting a leftover test address, testing.perplexity.com, to bypass Perplexity’s defenses. They also demonstrated how to exploit a timing flaw in Microsoft Edge, leveraging a race condition to switch the AI agent between its “think” and “act” modes at a crucial moment. The researchers noted that Opera reported finding the same flaw on its own around the same time and paid a reward for it.

Google initially identified the issue as CVE-2026-0628, rating it as a high severity due to the potential impact, although the National Institute of Standards and Technology has not yet assigned a score. CVE-2026-55945 was assigned to Edge, rated as a lower severity.

As of September 16, 2026, no public evidence showed any of the five methods being used in a real attack. The vulnerability requires the attacker to first convince the user to install the malicious extension, a common entry point for many browser attacks. LayerX described a related flaw, ClaudeBleed, in April, and Manifold Security reported a similar gap in a later version. The common thread is that integrating AI agents into browsers creates a pathway that browsers actively try to close, allowing a low-privilege extension to reach a high-privilege area.

For the two products with a CVE, the fix is to update Chrome to version 143.0.7499.192 or later and Edge to version 150.0.4078.48 or later. For Comet, Opera Neon, and Claude in Chrome, Forever Security said each vendor paid a reward but did not give a date for fixing the exact method it described. Users of those three should make sure their software is up to date and review the extensions they have installed.

Read the full article at The Hacker News