hacker-news · Crawled Sep 16, 2026

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

1 CVEs
Read original article ↗

AI Summary

Security researchers at Forever Security demonstrated a method to hijack AI assistants in multiple Chromium-based browsers and extensions by exploiting browser extension permissions to intercept trusted communication channels. The technique leverages two common extension permissions—content modification and network request manipulation—to inject malicious code into trusted AI service pages, enabling unauthorized access to sensitive capabilities such as file reading, screenshot capture, and AI agent control. While no active exploitation in the wild has been observed, the research highlights critical design flaws in how AI agents are integrated into browsers, with CVE-2026-0628 (Chrome) and CVE-2026-55945 (Edge) officially recognized and patched, while similar issues in Comet, Opera Neon, and Claude in Chrome remain less formally addressed.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 4 techniques