An installed extension can silently commandeer five browser AI assistants.
Public exploit code covers five products, while exact fixed versions are missing for some of them.
Gemini Live in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon, and Claude in Chrome on desktop Chromium-based browsers.
Silent browser-agent control, authenticated actions, and—in Chrome or Comet—local-file, screenshot, profile, history, camera, or microphone access
The extension does not merely alter a page: it impersonates an assistant's trusted front end and inherits authority over authenticated browser actions and, in some products, local data and sensors.
Detail and 2 sources
The starting point is an installed Chromium extension with broad host and declarative-network permissions; Edge and Claude additionally require debugger permission.
Request rewriting, content scripts, privileged-origin mistakes, and an Edge state race let the extension issue commands without a real user gesture.
Demonstrated outcomes include authenticated actions and, in Chrome or Comet, access to files, screenshots, profile data, history, camera, or microphone.
- access:local:unprivileged
- code running as an unprivileged local user
- interaction:none
- no user action required
- proposed:access:browser:installed-extension
- proposed; not yet curated