One Extension Hijacks AI in Five Chromium Products — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Forever Security demonstrated that one ordinary browser extension could hijack AI assistants in five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension.
- Gal Weizman first detailed the Chrome flaw publicly in March as 'GlicJack'; Google fixed it in Chrome version 143.0.7499.192 in early January 2026, and it is tracked as CVE-2026-0628 with a CISA rating of 8.8.
- Comet was the worst case — its AI-driven browser gave the hijacked agent broad powers, letting it read any file, list visited sites, take screenshots, and act as the user; researchers exploited a leftover test address, testing.perplexity.com, that was not locked down the same way as the main page.
- Microsoft Edge was the hardest to break — researchers combined a Microsoft marketing page allowed to send prompts with a race condition that switched the agent between 'think' and 'act' modes; Microsoft fixed it in Edge version 150.0.4078.48 on July 2 (CVE-2026-55945, rated 4.2).
- Anthropic rated the Claude in Chrome finding medium severity and paid a bounty, with Forever Security saying the company named it the first to report the flaw; researchers called it the mildest case since one extension was abusing another extension rather than a browser.
- Two common extension permissions — one that changes web pages (used by ad blockers) and declarativeNetRequest — were all an attacker needed to slip code into the trusted page each AI listens to and send it commands as if from the vendor.
- Neither CVE had been listed on the U.S. Known Exploited Vulnerabilities catalog as of September 16, 2026, and no public evidence showed any of the five methods being used in real attacks; all assume the attacker already got the user to install the extension.
Why it matters: The finding exposes a shared architectural weakness: placing an AI agent with file and camera access inside the browser creates a high-privilege target reachable from any installed extension using two common permissions. Only Chrome (CVE-2026-0628, fixed January 2026) and Edge (CVE-2026-55945, fixed July 2) shipped patches; Comet, Opera Neon, and Claude in Chrome received bounties without committed fix dates.
Ask SkimNews



