The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers at Forever Security showed that a single malicious browser extension could hijack the built-in AI assistants in five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and Claude in Chrome.
- Once installed, the extension could in some cases read local files, switch on the camera and microphone, take screenshots, or drive the AI agent to act on the attacker's behalf, with Comet described as the worst case.
- The Chrome flaw was fixed by Google in Chrome version 143.0.7499.192, and Microsoft fixed the Edge flaw in Edge version 150.0.4078.48, while Perplexity, Opera and Anthropic paid rewards but gave no fix date for the exact methods described.
- No real-world attacks using these methods have been seen, and every one of them requires the victim to have already installed the attacker's extension.
- The findings matter because they show that embedding AI agents inside browsers reopens a communication path that browsers normally work hard to close, so users should update their software and review their installed extensions.
What to watch next
- Whether Perplexity, Opera and Anthropic ship fixes or CVEs for the Comet, Opera Neon and Claude in Chrome findings, for which no fix dates were given.
- Whether any of the five methods appears on the U.S. Known Exploited Vulnerabilities catalog or shows up in real-world attacks.
- Whether Google, Microsoft and other vendors change how extensions can interact with trusted AI pages, such as locking down leftover test pages like testing.perplexity.com.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Forever Security
1 quote · 1 outlet
“Claude in Chrome is a browser extension, not a browser”
In the article
…from its main page, so Forever Security used a leftover test address, testing.perplexity.com, that was not locked down the same way. Claude in Chrome was the mildest case, and Forever Security said so directly. " Claude in Chrome is a browser extension, not a browser ," the company wrote, and it called the finding the least serious in the research because one extension was abusing another rather than an extension abusing a browser. Anthropic rated it medium severity and paid a…
Coverage1
All filed from India
Named United States · Anthropic · Google · Microsoft · Opera · Perplexity · Forever Security · Gal Weizman · LayerX · Manifold Security
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
