Researcher Has Found AI Browser Extension Flaws
Security gaps allowed malicious extensions to hijack AI assistants without requiring user interaction.
Updated on Sept. 28, 2026 in Artificial Intelligence

Live Poll
Do you trust AI assistants in your web browser to protect your private data?
Security researcher Gal Weizman discovered that malicious extensions can hijack AI assistants like Gemini Live, Perplexity Comet, and Claude. The research demonstrated that these attacks function without additional user clicks after the initial installation.
Why it matters
AI assistants rely on privileged browser components to function, creating a new attack surface for malicious software. If compromised, these tools can expose sensitive user information such as screenshots and browser profiles.
Researchers identified two CVEs, including CVE-2026-0628 in Chrome and a race condition in Microsoft Edge versions before 150.0.4078.48. These vulnerabilities exploited Chromium's declarativeNetRequest system to intercept trusted network requests.
The players
Gal Weizman
He is a security researcher who discovered methods for malicious browser extensions to hijack AI assistants.
This technology company developed the Chrome browser and awarded a bounty for the report of CVE-2026-0628.
Microsoft
This corporation manages the Edge browser and tracked a specific timing-based vulnerability as CVE-2026-55945.
Anthropic
This AI research company develops the Claude assistant and provided a bounty for findings related to its software.
The details
Malicious extensions manipulate the internal connections trusted by AI assistants by interfering with network requests. By utilizing race conditions, these extensions can feed prompts and activate features before standard browser security checks complete.
Timeline
Security research regarding browser extension vulnerabilities was published in 2026.
The Tech Race
This discovery highlights the evolving security challenges as AI assistants integrate more deeply into browser architectures. The findings underscore how existing trust models in systems like Chromium's declarativeNetRequest system are being tested by the rapid deployment of AI capabilities.
Users should ensure their browser software is updated to the latest versions to mitigate these discovered vulnerabilities. Practicing caution when installing browser extensions remains a vital step for protecting private data from potential hijacking.
The takeaway
Security research highlights that AI assistants are now a primary target for browser-based attacks. Users should consistently audit their installed extensions to ensure they have not granted unnecessary permissions to malicious third-party tools.
Further reading
Learn more about the latest developments in Artificial Intelligence.
Live Poll
Do you trust AI assistants in your web browser to protect your private data?







