One Extension Hijacked AI Agents in Five Browsers — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Forever Security demonstrated that a browser extension holding just two common permissions — one for modifying web pages and one for declarativeNetRequest — could inject commands into the trusted page each AI's "body" listens to (e.g., gemini.google.com, perplexity.ai) and hijack the agent across Chrome, Comet, Edge, Opera Neon, and Claude in Chrome.
- The Chrome finding, tracked as CVE-2026-0628 and rated 8.8/10 by CISA after NIST declined to score it, was first detailed publicly as GlicJack in March by researcher Gal Weizman and fixed in Chrome version 143.0.7499.192 in early January 2026.
- Microsoft Edge received CVE-2026-55945 (4.2 severity, fixed in Edge 150.0.4078.48 on July 2) but was the hardest to exploit, requiring researchers to chain a Microsoft marketing page takeover with a race condition that switched the agent between "think" and "act" modes mid-cycle.
- Perplexity Comet was the worst case because, as a fully AI-driven browser, its hijacked agent could read any file on the computer, list visited sites, take screenshots, and act as the user — Forever Security exploited a leftover test address, testing.perplexity.com, because the main page had been locked down.
- Opera Neon was the easiest target since its AI took orders from opera.com and Opera had not blocked extensions from running code there; Opera reportedly discovered the same flaw independently around the same time but still paid a reward.
- Claude in Chrome was rated the least serious finding by Forever Security itself because "Claude in Chrome is a browser extension, not a browser" — an extension abusing another extension — and Anthropic rated it medium severity.
- As of September 16, 2026 neither CVE appeared on the U.S. Known Exploited Vulnerabilities catalog, every method requires the user to already have the attacker's extension installed, and Forever Security earned roughly $20,000 in bounties across the five products.
Why it matters: Bloating a browser with an in-page AI agent reopens a privilege-escalation path that browsers spent a decade closing: a low-privilege extension — the kind any user might install for ad blocking — can now impersonate the vendor's trusted page and command a high-privilege AI body that can see the screen, open files, use the camera, and act as the user. Comet and Opera Neon remain unpatched for the exact method described, and Opera Neon's vendor-side fix timeline is not yet public.
Ask SkimNews



