Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Browser Extension Risks AI Assistant Security

Browser Extension Risks AI Assistant Security

Posted on September 16, 2026 By CWS

A recent analysis by security experts at Forever Security has revealed a significant vulnerability in AI assistants embedded in several popular Chromium-based browsers. The research highlights how a single browser extension can exploit security gaps in products like Chrome, Microsoft Edge, Opera Neon, and others, posing a substantial threat to user privacy and data integrity.

Extension Exploits in Chromium-Based Browsers

Forever Security’s findings demonstrate that once a potentially harmful extension is installed, it can manipulate the AI assistants within browsers such as Comet, Edge, and Opera Neon. This manipulation allows attackers to control AI agents and access sensitive functions such as reading local files and activating cameras or microphones. While these demonstrations are theoretical and not yet seen in real-world attacks, the implications are concerning.

The methodology involves compromising the trusted web pages that the AI agents rely on for instructions. By intercepting these pages, the extension can inject its own commands, effectively bypassing security protocols meant to segregate browser extensions from core functionalities.

Detailed Vulnerabilities and Vendor Responses

In Chrome, the vulnerability, known as GlicJack, was discovered earlier and addressed by Google in an update. However, the same technique was found applicable to other browsers with varying degrees of severity. Microsoft, for instance, issued a fix for Edge after a related vulnerability was reported, while the issues in Comet, Opera Neon, and Claude in Chrome are yet to receive specific CVE identifiers.

Forever Security’s report also outlines the potential impacts of these vulnerabilities. For example, the Comet browser, due to its deep AI integration, was flagged as particularly susceptible, capable of unauthorized file access and user activity monitoring. On the other hand, Claude in Chrome was considered less impactful, as it primarily involved extension abuse rather than browser-level exploitation.

Preventative Measures and Future Implications

To mitigate these security risks, users are advised to update their browsers to the latest versions and regularly review installed extensions for any unauthorized or suspicious activity. The ongoing discovery of such vulnerabilities underscores the challenges in securing AI-driven browser environments.

The overarching concern, as noted by Forever Security, is the inherent risk of embedding AI agents within browsers. This integration, while offering enhanced functionality, simultaneously reopens avenues for low-privilege extensions to access and potentially exploit high-privilege system components. Continuous vigilance and proactive security measures remain essential in safeguarding user privacy and data against such emerging threats.

As the landscape of AI technology evolves, so too must the strategies for securing its application within widely-used digital tools. The collaboration between security researchers and tech companies is crucial in addressing these vulnerabilities and maintaining robust cybersecurity defenses.

The Hacker News Tags:AI security, browser extensions, browser safety, browser vulnerabilities, Chrome, Claude in Chrome, Comet, CVE vulnerabilities, Cybersecurity, data protection, Edge, Forever Security, Opera Neon, tech news

Post navigation

Previous Post: Urgent Patch for Major Check Point Vulnerability Released
Next Post: Hackuity Secures $19M to Boost AI Vulnerability Management

Related Posts

New Flaws and AI Threats Shape Cybersecurity Landscape New Flaws and AI Threats Shape Cybersecurity Landscape The Hacker News
New Windows Vulnerability PoC Released Post Patch Update New Windows Vulnerability PoC Released Post Patch Update The Hacker News
Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit The Hacker News
40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials 40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials The Hacker News
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors The Hacker News
New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights Major ScreenConnect Security Flaw
  • Chrome and Firefox Address Critical Security Vulnerabilities
  • Critical Acronis cPanel Plugin Flaw Exploited
  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights Major ScreenConnect Security Flaw
  • Chrome and Firefox Address Critical Security Vulnerabilities
  • Critical Acronis cPanel Plugin Flaw Exploited
  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark