Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2026-0628 Vulnerabilities

Single Browser Extension Could Hijack AI Assistants Across Chrome, Edge, Comet, Opera Neon and Claude

Forever Security researchers showed how a browser extension could hijack AI assistants across Chrome, Edge, Perplexity Comet, Opera Neon and Claude, potentially accessing files and sensitive browser capabilities.

Security researchers have demonstrated a new class of browser attack in which a seemingly ordinary extension could potentially hijack powerful AI assistants integrated into modern Chromium-based browsers.

Researcher Gal Weizman of Forever Security demonstrated the technique against AI functionality in five products:

  • Google Chrome with Gemini
  • Perplexity Comet
  • Microsoft Edge
  • Opera Neon
  • Claude for Chrome

The research shows that once a malicious or compromised browser extension is running, it may be able to manipulate the trusted communication channel used by an AI assistant and effectively turn the assistant's own capabilities against the user.

Depending on the affected product, demonstrations included controlling AI-agent actions, accessing local files and, in Chrome's case, interacting with the device's camera and microphone.

The findings are security-research demonstrations. There is currently no evidence presented in the research that attackers are exploiting the technique in widespread real-world campaigns.

The Core Problem: AI Assistants Have More Power Than Normal Webpages

Modern AI-enabled browsers are significantly different from traditional browsers.

An ordinary webpage operates inside a restrictive security environment.

An AI browser agent, however, may need capabilities such as:

Viewing webpages

Opening files

Reading page content

Navigating websites

Interacting with browser tabs

Performing actions for the user

Accessing cameras or microphones when authorized

This creates an architectural model that Forever Security describes conceptually as an AI having a “brain” and a “body.”

The AI model acts as the brain.

A privileged browser component acts as the body, giving the AI the ability to interact with the user's browser and potentially the underlying device.

The security challenge is ensuring that only trusted instructions can control that body.

One Extension Can Cross That Trust Boundary

Forever Security found that browser extensions can potentially interfere with this communication model.

The researchers demonstrated that an extension using only two relatively common browser capabilities could perform the attack:

  • Permission to modify webpage content
  • declarativeNetRequest

These types of capabilities are not unusual.

Ad blockers, privacy tools, content modifiers and many other legitimate browser extensions may require similar access.

The problem emerges when an extension can manipulate the trusted webpage or communication mechanism through which the browser's AI receives instructions.

The attack can conceptually work like this:

User installs browser extension

↓

Extension runs with granted permissions

↓

Extension modifies trusted AI-facing browser content

↓

AI communication channel is manipulated

↓

Attacker-controlled instruction reaches AI agent

↓

AI interprets instruction as trusted

↓

AI's privileged capabilities execute the action

Instead of directly requesting sensitive permissions itself, the extension can potentially make the AI assistant perform the sensitive operation.

From Extension Permissions to AI Agent Control

This creates an important change in the security model.

Traditionally:

Extension permissions → Extension capabilities

With agentic browsers:

Extension permissions → AI assistant → AI capabilities

That second model can significantly increase the impact of a malicious extension.

An extension that would normally have limited access may potentially reach capabilities exposed through the AI agent.

The security issue is therefore not necessarily that the extension itself can directly access every sensitive resource.

Instead, it may manipulate a more privileged AI component into performing actions on its behalf.

Chrome: CVE-2026-0628

The Chrome implementation was tracked as:

CVE-2026-0628

with a CVSS score of 8.8.

Google patched the issue in Chrome 143.0.7499.192 in January 2026.

Forever Security demonstrated that the weakness could allow an extension to manipulate Chrome's Gemini-powered functionality.

The potential capabilities demonstrated in the research were particularly significant because Chrome's AI integration could interact with:

  • Local files
  • Camera
  • Microphone

This meant the researchers could potentially transform an extension compromise into access to capabilities considerably beyond normal webpage interaction.

Local File Access Demonstrated

Researchers demonstrated local-file access against Chrome and Perplexity Comet.

This represents an important security boundary.

A normal website cannot simply browse arbitrary files on a user's computer.

Browser security mechanisms are specifically designed to prevent websites from freely accessing local files.

But an AI assistant designed to help users work with local content may legitimately possess functionality for opening or processing files.

If an attacker can control that assistant, the attacker may indirectly reach those capabilities.

The attack model becomes:

Malicious extension

→ Hijacked AI assistant

→ AI accesses local file

→ Sensitive information becomes exposed

This could potentially place documents, development files and other locally stored information at risk, depending on the permissions and design of the affected assistant.

Camera and Microphone Access Demonstrated in Chrome

The Chrome demonstration went even further.

Forever Security showed that the hijacked AI functionality could be manipulated into activating the computer's camera and microphone.

This demonstrates why AI-agent security boundaries are becoming increasingly important.

The extension does not necessarily need direct permission for every sensitive operation if it can influence another trusted component that already possesses those capabilities.

This resembles a form of confused-deputy problem, where a trusted component with greater privileges is manipulated into performing actions on behalf of a less-trusted component.

AI Agent Control Across Multiple Browsers

Forever Security demonstrated related techniques against:

Perplexity Comet

Microsoft Edge

Opera Neon

Claude for Chrome

In the Comet, Edge, Opera Neon and Claude demonstrations, researchers showed that the extension could drive AI-agent functionality to perform attacker-directed actions.

The exact capabilities differed between products.

That distinction matters because the research does not establish that every affected assistant exposes identical functionality.

For example:

Product Demonstrated Impact
Chrome / Gemini AI control, local-file access, camera and microphone interaction
Perplexity Comet AI-agent control and local-file access
Microsoft Edge AI-agent manipulation
Opera Neon AI-agent manipulation
Claude for Chrome AI-agent manipulation

The broader problem, however, was consistent: an extension operating inside the browser could interfere with the trust relationship between the browser and its AI assistant.

Why Traditional Extension Permissions May No Longer Be Enough

Browser-extension security models were largely designed before browsers contained autonomous AI agents.

Historically, users could evaluate an extension based on permissions such as:

Read and change website data

or capabilities involving request modification.

But an AI-enabled browser changes the consequences of those permissions.

Suppose an extension can modify a webpage trusted by an AI agent.

And suppose the AI agent can:

Read local files

Interact with websites

Send messages

Access authenticated sessions

Operate cameras

Use microphones

Then the effective power of the extension may become much greater than what the permission prompt originally communicates.

This creates a new security question:

Should extensions be allowed to modify the same interfaces trusted by privileged AI agents?

The AI Becomes a Confused Deputy

The research highlights a classic cybersecurity problem in a new environment: the confused deputy.

Imagine:

Component A: Browser extension

Low trust / limited privileges.

Component B: AI agent

High trust / powerful privileges.

If Component A can send instructions that Component B mistakenly considers trusted, the attacker may effectively inherit Component B's capabilities.

The attacker does not necessarily break the AI model itself.

Instead, they manipulate the mechanism used to communicate with it.

That distinction is important.

The vulnerability is fundamentally about trust boundaries and authorization, not about the AI becoming malicious on its own.

A Malicious Extension Must Already Be Installed

The research also has an important prerequisite.

The attacker needs a malicious or compromised extension already running inside the victim's browser.

This is not a scenario where merely visiting any website automatically compromises every AI browser.

A more realistic attack sequence would be:

User installs malicious extension

or

Existing trusted extension becomes compromised

↓

Extension receives browser permissions

↓

Extension interacts with AI trust channel

↓

AI assistant hijacked

↓

Privileged AI capabilities abused

This makes extension security a critical defensive layer.

Why Compromised Legitimate Extensions Matter

Attackers do not necessarily need to convince users to install an obviously malicious extension.

A legitimate extension could potentially become dangerous if:

  • Its developer account is compromised
  • Its update infrastructure is hijacked
  • The extension is sold to a malicious operator
  • A malicious update is published
  • Its dependencies are compromised

This type of supply-chain compromise has occurred repeatedly within browser-extension ecosystems.

AI-enabled browsers potentially increase the impact because a compromised extension may now have another high-value target inside the browser:

the AI agent itself.

No Evidence of Active Exploitation

Forever Security's findings are proof-of-concept security research, not evidence of an active attack campaign.

The demonstrations establish that the security boundaries could be crossed under the tested conditions.

They do not establish that attackers have already exploited these techniques against users in the wild.

This distinction is important when assessing the current risk.

The findings should therefore be treated as an architectural warning for browser and AI developers rather than evidence of an ongoing mass compromise.

What Users Should Do

Users of AI-enabled browsers should pay particular attention to installed extensions.

Recommended actions include:

  • Keep browsers updated.
  • Keep AI extensions updated.
  • Remove extensions that are no longer required.
  • Avoid installing extensions from unknown developers.
  • Review permissions requested by extensions.
  • Minimize extensions capable of modifying every website.
  • Review extensions after major browser or AI updates.
  • Avoid unnecessary extensions on systems containing highly sensitive information.
  • Use enterprise extension allowlisting on managed endpoints.

Chrome users should ensure they are running a version containing Google's fix for CVE-2026-0628 or a newer supported release.

Enterprise Security Teams Should Control Extensions

Organizations deploying AI-enabled browsers should consider browser extensions part of their AI security strategy.

Enterprise administrators can implement:

Extension allowlisting

Only explicitly approved extensions can execute.

Permission monitoring

Extensions requesting broad website access should receive additional scrutiny.

Extension inventory

Security teams should know which extensions are installed across managed endpoints.

Developer verification

Organizations should evaluate extension publishers and update histories.

Rapid revocation

Security teams should be able to remotely disable a compromised extension.

Browser telemetry

Unusual extension activity should be correlated with browser and endpoint events.

Organizations should also evaluate whether sensitive users need every available AI-agent capability enabled.

Browser Developers Need Stronger Isolation

The deeper solution needs to come from browser and AI-platform architecture.

A privileged AI assistant should not assume that content originating from a trusted webpage is trustworthy if another extension can freely modify that page.

Security controls should distinguish between:

User-generated instruction

Website-generated content

Extension-generated content

AI-generated content

External tool output

These sources should not automatically receive the same level of trust.

AI agents also need strong authorization boundaries before performing sensitive operations.

Actions involving:

  • Local files
  • Camera
  • Microphone
  • Credential stores
  • Account settings
  • Financial transactions
  • Sending messages
  • Downloading or uploading files

should receive additional security controls appropriate to their risk.

Security Takeaway

Forever Security's research demonstrates a fundamental challenge facing the next generation of web browsers.

Browser extensions were designed to modify webpages.

AI assistants are being designed to act on behalf of users.

Combining those two capabilities creates a new security boundary.

If an extension can manipulate the interface trusted by an AI assistant, the extension may potentially turn the assistant's privileged capabilities against the user.

The attack can therefore transform:

Ordinary Browser Extension

into:

Extension → AI Agent → Privileged Browser Actions

The research does not show that AI browsers are currently being compromised at scale, and the attacker still needs an extension running in the victim's browser.

But it demonstrates why browser-extension permissions that were acceptable in the pre-agentic web may carry significantly greater risk when an AI assistant can access files, authenticated services, sensors and other sensitive resources.

As browsers evolve from passive tools into autonomous agents, their security architecture must evolve with them.

The critical principle is simple:

An AI agent should never automatically trust something merely because it came from inside the browser.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.