Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exposing the Vulnerabilities of Chromium-Based AI Assistants: A Threat to Browser Security




A recent discovery has revealed that a single ordinary browser extension can take control of the AI assistants built into five Chromium-based products. The extension can access each product's built-in AI with a single click, allowing an attacker to drive the AI agent to act on their behalf. This vulnerability highlights the need for improved security measures to protect Chromium-based AI assistants.



  • A vulnerability has been discovered in Chromium-based AI assistants, allowing a single browser extension to take control of the AI assistants in five products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome.
  • The extension can access each product's built-in AI with a single click, allowing an attacker to drive the AI agent to act on their behalf.
  • The vulnerability is attributed to a flaw in the design of the AI assistants, where the extension can seize the trusted page and send its own commands to the AI.
  • The Chrome case is not new, as a similar issue was fixed by Google in early January 2026, while the other four products were not.
  • The discovery highlights the need for improved security measures to protect Chromium-based AI assistants, and emphasizes the importance of robust security testing and prioritizing product security.



  • The recent discovery of a vulnerability in Chromium-based AI assistants has sent shockwaves throughout the cybersecurity community. Security researchers at Forever Security have demonstrated that a single ordinary browser extension can take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension.

    The findings, which were published on September 16, 2026, reveal that the extension can access each product's built-in AI with a single click, allowing an attacker to drive the AI agent to act on their behalf. This can result in a range of malicious activities, including reading local files, taking screenshots, and controlling the AI agent.

    The vulnerability is attributed to a flaw in the way the AI assistants are designed. According to Forever Security, each AI assistant has a "body" and a "brain" - the body is responsible for interacting with the user and the brain is responsible for receiving commands from the company's servers. The body is only supposed to take orders from a trusted web page, but the extension is able to seize this trusted page and send its own commands to the AI.

    The researchers used a combination of two common permissions - one that changes web pages and one called declarativeNetRequest that changes the browser's network traffic - to slip their own code into the trusted page and speak to the AI as if it were the vendor.

    The Chrome case is not new, as Forever Security researcher Gal Weizman first detailed it publicly in March 2026. Google fixed the issue in early January 2026 in Chrome version 143.0.7499.192. However, the other four products - Comet, Edge, Opera Neon, and Claude in Chrome - were not as fortunate, with Forever Security adding these findings to the list this year.

    Using the same idea, Forever Security was able to reach the built-in AI in Comet, Edge, Opera Neon, and Claude in Chrome. However, only the Edge finding received a CVE, CVE-2026-55945, a lower-severity issue rated 4.2 that Microsoft fixed in Edge version 150.0.4078.48 on July 2.

    The Comet, Opera Neon, and Claude findings have no CVE and rest on Forever Security's own account. The company said it earned about $20,000 in bug bounties across the five products, though its per-product figures add up to $20,500.

    The researchers listed what each attack could do, including:

    * Read local files
    * Take screenshots
    * Control the AI agent
    * Leak browser profile
    * Leak browsing history
    * No clicks needed

    The common thread, Forever Security said, is that putting an AI agent inside the browser reopens a path that browsers work hard to close, allowing a low-privilege extension to reach a high-privilege part of the browser. This is a critical concern, as it highlights the vulnerability of Chromium-based AI assistants to exploitation.

    The findings are not new attacks, but rather demonstrations of the vulnerability. Each requires the attacker's extension to be already running in the victim's browser. The researchers emphasized that no public evidence showed any of the five methods being used in a real attack.

    As of September 16, 2026, neither CVE was listed on the U.S. Known Exploited Vulnerabilities catalog, and no public evidence showed any of the five methods being used in a real attack. However, users of Comet, Opera Neon, and Claude in Chrome are advised to make sure their software is up to date and review the extensions they have installed.

    The implications of this discovery are significant, and highlight the need for improved security measures to protect Chromium-based AI assistants. Forever Security's research serves as a wake-up call for the industry, emphasizing the importance of robust security testing and the need for vendors to prioritize the security of their products.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exposing-the-Vulnerabilities-of-Chromium-Based-AI-Assistants-A-Threat-to-Browser-Security-ehn.shtml

  • https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html

  • https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants


  • Published: Wed Sep 16 12:36:00 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us