← All articles

One malicious extension can hijack the built-in AI in several browsers

Researchers at Forever Security showed that a single malicious browser extension can hijack the AI assistant built into several AI-enabled browsers, including Chrome, Edge, Comet, Opera Neon, and Claude in Chrome. The core problem is that putting an AI agent inside the browser reopens a privilege-escalation path browsers normally work to close, letting a low-privilege extension reach a high-privilege part of the browser. Two of the findings received identifiers, one in Chrome, patched in January, and one in Edge, patched in July, while the others were fixed through bug bounties without dates. There is no evidence of real-world use yet, and each method still requires the user to install the extension.

Check
Update Chrome, Edge, and other AI-enabled browsers to their latest versions, review installed extensions and remove untrusted ones, and restrict extension installation through browser policy where possible.
Affected
Users of browsers with a built-in AI assistant who install a malicious extension; it can escalate from its low privileges to the high-privilege in-browser AI agent, controlling the assistant and its access.
Fix
Keep AI-enabled browsers updated, enforce extension allowlisting by policy, limit what the built-in AI agent can access, and treat the in-browser AI assistant as a privilege boundary extensions must not reach.