One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Summary
Security researchers discovered that a single malicious browser extension could hijack AI assistants in five Chromium-based products (Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome) by exploiting how these AIs are built with a "body" in the browser that listens only to trusted company websites. The extension could read files, control the AI to act on behalf of attackers, and access cameras and microphones, though these are researcher demonstrations requiring the malicious extension to already be installed. The vulnerabilities work because extensions with common permissions (like those used by ad blockers) can inject code into the trusted websites that the AI body listens to.
Solution / Mitigation
Google fixed the Chrome vulnerability (CVE-2026-0628) in Chrome version 143.0.7499.192 released in early January 2026. Microsoft fixed the Edge vulnerability (CVE-2026-55945) in Edge version 150.0.4078.48 released on July 2. The source does not mention fixes for Perplexity Comet, Opera Neon, or Claude in Chrome.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html
First tracked: September 16, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%