Malicious Browser Extension Can Hijack AI Assistants Across Multiple Chromium Browsers
A single malicious browser extension was able to compromise AI assistants across five Chromium-based products by abusing two commonly granted permissions — web page modification and network traffic interception — to inject code into trusted pages. This attack surface exists because browsers routinely grant extensions broad permissions without sufficiently isolating privileged AI assistant contexts, and because vendors sharing a common codebase often inherit each other's vulnerabilities. The consequences are severe: attackers could exfiltrate files, access cameras and microphones, leak browsing history, and take actions on behalf of the user. This case highlights how the rapid integration of AI assistants into browsers dramatically expands the blast radius of what was previously a well-understood extension security problem, and that patching one vendor is not sufficient when a shared architectural flaw affects the entire ecosystem.
Tactical Insight
Immediate actions
- Apply the January 2026 patch for CVE-2026-0628 in Chrome and CVE-2026-55945 in Edge immediately, and monitor vendor advisories for Comet, Opera Neon, and Claude patches.
- Audit all currently installed browser extensions across the organization and remove any with web page modification or network traffic interception permissions that are not business-critical.
- Restrict users from installing unapproved browser extensions via Group Policy, MDM, or browser enterprise management controls.
Configuration hardening
- Enforce an allowlist of approved extensions using enterprise browser management tools (e.g., Chrome Enterprise, Edge for Business) so only vetted extensions can be installed.
- Configure browsers to isolate AI assistant pages in dedicated profiles or sandboxed environments to limit cross-context code injection opportunities.
- Disable or restrict camera, microphone, and local file access permissions for browser-based AI assistants unless explicitly required.
Detection measures
- Deploy endpoint detection tools capable of flagging browser extensions that request high-risk permission combinations (web page modification + network interception).
- Establish logging and alerting for anomalous browser network traffic patterns that may indicate session hijacking or data exfiltration by a malicious extension.
- Conduct periodic extension permission reviews as part of your vulnerability management cycle to catch newly introduced or updated extensions with escalated privileges.