Skip to finding
§
Medium
Browser agents
Confirmed
CVE-2026-0628

An installed extension can silently commandeer five browser AI assistants.

Public exploit code covers five products, while exact fixed versions are missing for some of them.

Affects

Gemini Live in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon, and Claude in Chrome on desktop Chromium-based browsers.

What it enables

Silent browser-agent control, authenticated actions, and—in Chrome or Comet—local-file, screenshot, profile, history, camera, or microphone access

Get an otherwise ordinary extension installed with the permissions required by the applicable variant.→↓Use declarative request rewriting or a content script to reach a web origin the browser agent treats as trusted.→↓Issue privileged browser commands or force a prompt without a real user gesture.→↓Read local or authenticated data in Chrome and Comet, or direct Comet, Edge, Opera Neon, or Claude to act through the user’s authenticated browser context.
Why this matters

The extension does not merely alter a page: it impersonates an assistant's trusted front end and inherits authority over authenticated browser actions and, in some products, local data and sensors.

Detail and 2 sources
Required access

Control of an installed Chromium extension with ordinary broad host and declarative-network permissions; the Edge and Claude variants additionally used debugger permission

Proof of concept

Public exploit code

The starting point is an installed Chromium extension with broad host and declarative-network permissions; Edge and Claude additionally require debugger permission.

Request rewriting, content scripts, privileged-origin mistakes, and an Edge state race let the extension issue commands without a real user gesture.

Demonstrated outcomes include authenticated actions and, in Chrome or Comet, access to files, screenshots, profile data, history, camera, or microphone.

Evidence
Researcher published technical exploit code and per-browser architecture detailsResearcher demonstrated all five variants and reported vendor bounty outcomesExact fixed versions were not supplied for every affected product
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026