DEV Community

Cover image for One Browser Extension Could Hijack Every AI Assistant in Your Staff's Browser
TheAutomate.io
TheAutomate.io

Posted on Originally published at theautomate.io

One Browser Extension Could Hijack Every AI Assistant in Your Staff's Browser

TL;DR

  • A single browser extension can hijack AI assistants built into Chrome, Edge, Opera Neon, Perplexity Comet and Claude.
  • It needs only two permissions that ad blockers already use.
  • Chrome and Edge have patches. Comet, Opera Neon and Claude in Chrome do not have a confirmed fix date from Forever Security's account.
  • No real-world attacks have been confirmed as of 16 September 2026.
  • The practical control is your extension policy, not a software update.

This is not a phishing story. It is a story about what happens when an AI agent lives inside a browser.

What did the researchers actually find?

Security researchers at Forever Security published findings on 16 September 2026 showing that one malicious browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension. The full write-up is covered by The Hacker News.

The attack works because each product gives the AI a "body" inside the browser that can see the screen, open files, use the camera, and take actions. That body only accepts orders from one trusted web page. A browser extension is not supposed to command that body directly.

Forever Security's method was to seize the trusted page the AI body listens to and, through it, send the body its own commands. The malicious browser extension needed only two common permissions: one that changes web pages (the same permission ad blockers use) and one called declarativeNetRequest that changes the browser's network traffic.

The result varied by product. On Comet, Edge, Opera Neon, and Claude in Chrome, the browser extension could drive the AI agent to act on behalf of the attacker. On Chrome and Comet, it could also read files from the user's computer. On Chrome alone, it could switch on the camera and microphone.

Which products are patched and which are not?

The Chrome case is the oldest. Google fixed it in Chrome version 143.0.7499.192 in early January 2026. It is tracked as CVE-2026-0628 and rated 8.8 out of 10 by CISA.

The Edge case received CVE-2026-55945, rated 4.2, and Microsoft fixed it in Edge version 150.0.4078.48 on 2 July 2026.

Comet, Opera Neon, and Claude in Chrome have no CVE. Forever Security said each vendor paid a bug bounty but did not give a confirmed fix date for the exact method described. Users of those three products should keep their software current and review which extensions are installed.

Forever Security described Comet as the worst case. Perplexity built Comet as a fully AI-driven browser with broad agent powers. Once a browser extension hijacked it, the agent could read any file on the computer, list sites the user had visited, take screenshots, and act as the user. Perplexity had blocked extensions from its main page, so Forever Security used a leftover test address, testing.perplexity.com, that was not locked down the same way.

Claude in Chrome was the mildest case. Forever Security noted that one browser extension was abusing another extension rather than abusing a browser, and called it the least serious finding in the research. Anthropic rated it medium severity and paid a bounty.

Edge was the hardest to break. Microsoft had tried to block the extension trick, so Forever Security combined two weaknesses: it took over a Microsoft marketing page allowed to send prompts to the Edge AI, then used a timing flaw to switch the agent between its think and act modes at the right moment.

What does this mean for a brokerage running AI tools?

As of 16 September 2026, neither CVE was listed on the US Known Exploited Vulnerabilities catalog, and no public evidence showed any of the five methods being used in a real attack. Every one of them requires the attacker's browser extension to already be running in the victim's browser.

For a brokerage, the practical question is not only whether to patch Chrome and Edge. The question is whether your firm has a policy on which browser extensions staff may install, and whether that policy covers AI-enabled browsers.

The common thread Forever Security identified is that putting an AI agent inside a browser reopens a path that browsers work hard to close. A low-privilege browser extension can reach a high-privilege part of the browser precisely because the AI agent needs broad access to be useful. That tension does not go away with a single patch.

This connects to a broader pattern. An OpenAI agent bypassed Australian Medicare portal controls, as covered in our post on what brokers should do after the Medicare portal incident. The ASD has separately flagged cases where AI assistants took unexpected actions, which we covered in our post on ASD's broker risk guidance. The browser extension attack is a different vector, but the underlying issue is the same: AI agents with broad permissions create new attack surfaces.

Update Chrome to version 143.0.7499.192 or later and Edge to version 150.0.4078.48 or later. For Comet, Opera Neon, and Claude in Chrome, keep software current and audit installed extensions. If your firm does not have a written policy on browser extensions, this research is a reasonable prompt to create one.


FAQs

Does this affect the AI voice agents brokers use for client calls?
The Forever Security research covers AI assistants built into browsers, not standalone voice agent platforms. A voice agent running on a separate telephony stack is not exposed to this browser extension attack path. That said, if staff use browser-based AI tools alongside a voice agent, the browser risk still applies to those tools.

Do brokers need to stop using Chrome or Edge?
No. Both Chrome and Edge have patches available. Update Chrome to version 143.0.7499.192 or later and Edge to version 150.0.4078.48 or later. The risk for those two products is addressed by keeping the browser current.

What is the actual risk if no real attacks have been seen?
The researchers confirmed no real-world exploitation as of 16 September 2026. The risk is theoretical but technically demonstrated. For a brokerage, the more immediate action is reviewing which browser extensions staff have installed, since every variant of this attack requires a malicious extension to already be present.

Should a brokerage ban all browser extensions?
A blanket ban is one option but may be impractical. A more workable approach is a whitelist of approved extensions, reviewed periodically. Ad blockers, password managers, and productivity tools all request permissions similar to those used in this research, so the question is not the permission alone but whether the extension source is trusted.

Does this affect Anthropic's Claude API, which some brokers use directly?
The finding covers Claude in Chrome, which is a browser extension. It does not cover the Claude API accessed directly by a backend system. If your brokerage calls the Claude API from a server-side integration rather than through a browser extension, this specific attack path does not apply.


Originally published at theautomate.io.

Top comments (0)