Researcher Has Found AI Browser Extension Flaws

Security gaps allowed malicious extensions to hijack AI assistants without requiring user interaction.

Updated on Sept. 28, 2026 in Artificial Intelligence

Isometric editorial illustration of a complex network of interconnected hardware modules and fiber-optic pathways, visualizing software architecture vulnerabilities.
Security researcher Gal Weizman identified vulnerabilities in browser extensions that allow malicious software to compromise AI assistants like Gemini, Claude, and Perplexity. AI Illustration. Upload story photo >

Live Poll

Do you trust AI assistants in your web browser to protect your private data?

Security researcher Gal Weizman discovered that malicious extensions can hijack AI assistants like Gemini Live, Perplexity Comet, and Claude. The research demonstrated that these attacks function without additional user clicks after the initial installation.

Why it matters

AI assistants rely on privileged browser components to function, creating a new attack surface for malicious software. If compromised, these tools can expose sensitive user information such as screenshots and browser profiles.

Researchers identified two CVEs, including CVE-2026-0628 in Chrome and a race condition in Microsoft Edge versions before 150.0.4078.48. These vulnerabilities exploited Chromium's declarativeNetRequest system to intercept trusted network requests.

The players

Gal Weizman

He is a security researcher who discovered methods for malicious browser extensions to hijack AI assistants.

Google

This technology company developed the Chrome browser and awarded a bounty for the report of CVE-2026-0628.

Microsoft

This corporation manages the Edge browser and tracked a specific timing-based vulnerability as CVE-2026-55945.

Anthropic

This AI research company develops the Claude assistant and provided a bounty for findings related to its software.

The details

Malicious extensions manipulate the internal connections trusted by AI assistants by interfering with network requests. By utilizing race conditions, these extensions can feed prompts and activate features before standard browser security checks complete.

Timeline

  1. Security research regarding browser extension vulnerabilities was published in 2026.

The Tech Race

This discovery highlights the evolving security challenges as AI assistants integrate more deeply into browser architectures. The findings underscore how existing trust models in systems like Chromium's declarativeNetRequest system are being tested by the rapid deployment of AI capabilities.

Users should ensure their browser software is updated to the latest versions to mitigate these discovered vulnerabilities. Practicing caution when installing browser extensions remains a vital step for protecting private data from potential hijacking.

The takeaway

Security research highlights that AI assistants are now a primary target for browser-based attacks. Users should consistently audit their installed extensions to ensure they have not granted unnecessary permissions to malicious third-party tools.

Further reading

Learn more about the latest developments in Artificial Intelligence.

Live Poll

Do you trust AI assistants in your web browser to protect your private data?