Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

One browser extension could hijack AI assistants in five browsers

Forever Security researchers say a single ordinary extension gained one-click control of built-in AI assistants across Chrome, Comet, Edge, Opera Neon and Claude in Chrome.

By The Agentic Times ·

One browser extension could hijack AI assistants in five browsers
· Image: thehackernews.com

Security researchers at Forever Security have demonstrated that a single ordinary browser extension could take control of the AI assistants built into five Chromium-based products, according to a report published on 16 September 2026. The affected products were Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. That covers assistants from Google, Microsoft, Opera, Anthropic and Perplexity.

According to the researchers, once the extension was installed, it could access each product's built-in AI with a single click. The report specifically names Comet, Edge and the other products as reachable in this way. The researchers describe the extension as ordinary, meaning it did not rely on an exploit unique to one vendor but on the level of access that extensions are normally granted inside the browser.

The underlying problem, as recorded in the incident summary drawn from the research, is excessive permissions. AI assistants are increasingly built directly into the browser, where they can read pages, act on behalf of the user and hold conversations about whatever is on screen. An extension that sits in the same browser can, in the researchers' demonstration, reach those assistants and drive them.

That matters because an AI assistant inside a browser is a privileged thing. It sees what the user sees, and in the case of agentic assistants it can also click, type and submit on the user's behalf. Control of the assistant is therefore closer to control of the session than control of a single web page.

The finding is currently at the report stage. The published research does not state that any real users were attacked, and the sources give no evidence of exploitation in the wild. Nor do the sources record responses, fixes or mitigations from Google, Microsoft, Opera, Anthropic or Perplexity. The Agentic Times has not seen statements from the five vendors on the research.

For users, the practical point from the research is narrow but useful. The risk is not in the assistant alone, and not in the extension alone, but in the two sharing a browser. Anyone relying on a built-in AI assistant for sensitive work should treat every installed extension as something with potential reach into that assistant, since the researchers showed that reach required only a single click after installation.

We will update this story if the vendors respond or if Forever Security publishes further technical detail on how each of the five products was reached.

Sources

  1. thehackernews.comhttps://thehackernews.com/2026/09/one-extension-could-hijack-ai.html