Browser Extension Hijacks Multiple AI Assistants
Security researchers at Forever Security demonstrated that a single browser extension could hijack AI assistants across five Chromium-based products. This included Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension. Once installed, the extension gained control of the built-in AI tools with a single click, allowing unauthorized access. The full extent of potential misuse remains under investigation.
Severity: High · Category: Supply Chain
Impact: Unauthorized access and control over multiple production AI assistants, potentially leading to data exfiltration or malicious prompt injection.
Source: The Hacker News · Sep 16 2026 · Original source
What Happened
Security researchers at Forever Security demonstrated that a single, ordinary browser extension could take control of AI assistants built into five Chromium-based products. These products included Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click, enabling various unauthorized actions. The extension could drive the AI agent to act on behalf of an attacker in Comet, Edge, Opera Neon, and Claude in Chrome. For Chrome and Comet, it could read files from the user's computer, and specifically for Chrome, it could also activate the camera and microphone. These findings represent researcher demonstrations and were not observed as attacks in the wild; each required the attacker's extension to be already running in the victim's browser.
Timeline
- Early January 2026 — Google fixed the Chrome vulnerability (GlicJack) in Chrome version 143.0.7499.192.
- March — Forever Security researcher Gal Weizman first publicly detailed the Chrome case as GlicJack.
- April — Security firm LayerX described a related flaw, called ClaudeBleed.
- July — Manifold Security reported that a similar gap remained open in a later version of the Claude in Chrome extension.
- July 2 — Microsoft fixed the Edge vulnerability in Edge version 150.0.4078.48.
- September 16, 2026 — The Hacker News article detailing the findings was published.
Technical Analysis
The underlying mechanism for these AI assistants involves a "body" within the browser that can interact with the screen, open files, use the camera, and perform actions, and a "brain" running on company servers that issues commands to the body. The browser's AI "body" is designed to only accept orders from a single trusted web page, such as gemini.google.com for Chrome or perplexity.ai for Comet. Browser extensions are typically restricted from directly controlling the browser itself, instead being limited to modifying web pages.
Forever Security's method circumvented this by seizing the trusted web page that the AI body listens to. Through this compromised trusted page, the extension was able to send its own commands to the AI, effectively impersonating the vendor. This exploit required only two common browser permissions: one that allows changing web pages (similar to ad blockers) and another called `declarativeNetRequest`, which modifies browser network traffic. These permissions enabled the extension to inject its code into the trusted page and communicate with the AI as if it were the legitimate vendor.
Specific product exploits varied: For Perplexity Comet, Forever Security utilized a leftover test address, `testing.perplexity.com`, which lacked the same security lockdown as the main `perplexity.com` page. For Microsoft Edge, researchers combined two weaknesses: taking over a Microsoft marketing page that was permitted to send prompts to the Edge AI, and a timing flaw (race condition) to switch the AI agent between its "think" and "act" modes at a precise moment to execute a prompt. Opera Neon's AI accepted orders from `opera.com`, and Opera had not prevented extensions from running code on that page, allowing direct command injection. The common vulnerability across these cases is that integrating an AI agent within the browser reintroduces a pathway that browsers typically work to secure, allowing a low-privilege extension to access a high-privilege browser component.
Impact
The demonstrated vulnerabilities allowed an installed browser extension to gain unauthorized access and control over AI assistants in five Chromium-based products. The specific capabilities varied by product:
* **Chrome**: Could read local files, access the camera and microphone, leak the browser profile, and take screenshots. * **Comet**: Could read local files, control the AI agent, leak the browser profile, leak browsing history, and take screenshots. Researchers described Comet as the "worst case" due to its agent's broad powers, allowing it to read any file, list visited sites, take screenshots, and act as the user once hijacked. * **Edge**: Could control the AI agent. * **Opera Neon**: Could control the AI agent. * **Claude in Chrome**: Could control the AI agent. This was considered the "mildest case" as it involved one extension abusing another, rather than an extension abusing a browser.
In all five cases, the extension could perform these actions with "no clicks needed" once installed. The Chrome vulnerability (GlicJack) is tracked as CVE-2026-0628 and received a severity rating of 8.8 out of 10 by CISA. The Edge finding is tracked as CVE-2026-55945, with a lower severity rating of 4.2. The Comet, Opera Neon, and Claude in Chrome findings do not have assigned CVEs. Forever Security reported earning approximately $20,000 in bug bounties across the five products, with specific amounts: $7,000 for Chrome, $7,000 for Comet, $5,000 for Edge, $900 for Opera Neon, and $600 for Claude in Chrome, totaling $20,500. As of September 16, 2026, neither CVE was listed on the U.S. Known Exploited Vulnerabilities catalog, and there was no public evidence indicating any of the five methods had been used in real-world attacks.
Discovery & Response
The vulnerabilities were discovered and demonstrated by security researchers at Forever Security. Google addressed the Chrome vulnerability (CVE-2026-0628) in early January 2026, releasing a fix in Chrome version 143.0.7499.192. Microsoft fixed the Edge vulnerability (CVE-2026-55945) on July 2, with the fix included in Edge version 150.0.4078.48. Forever Security received bug bounties for all five products, totaling approximately $20,000. Anthropic rated the Claude finding as medium severity and paid a bounty. Opera reported that it had independently discovered the same flaw in Opera Neon around the same time as Forever Security but still issued a reward. For Comet, Opera Neon, and Claude in Chrome, while vendors paid rewards, no specific dates for fixing the exact methods described by Forever Security were provided. Users of these three products are advised to ensure their software is up to date and to review their installed extensions.
How Fencio prevents this
The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.
Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.