A cybersecurity researcher has uncovered a significant vulnerability that allows standard browser extensions—like those used for blocking ads—to bypass the AI assistants integrated into five major browsers. The method, discovered by Gal Weizman of Forever Security, exploits the ability of these extensions to modify web content and redirect network requests. Typically, such permissions are granted to ad blockers and other browser tools. This allows malicious code to be inserted into a trusted website, making it appear as if the publisher itself is communicating with the AI assistant. The attack requires no action from the user—no clicking or interaction—and the AI assistant executes instructions from the extension without checking their origin.
The vulnerability affected several browsers, including Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. Google fixed its vulnerability, CVE-2026-0628, in Chrome version 143.0.7499.192, released in January. This flaw had a severity score of 8.8 out of 10 and could allow attackers to access files, the microphone, the camera, and even take screenshots of the user. Microsoft addressed its vulnerability, CVE-2026-55945, starting in July, with a lower severity score of 4.2. This flaw allowed attackers to bypass the AI agent and take control of the browser. Opera Neon, Comet, and Claude in Chrome did not receive assigned CVE identifiers, but the attacks on these platforms allowed the exfiltration of emails, displayed data, or even full access to the file system and the AI agent.
What makes these attacks particularly concerning is that they do not rely on traditional malicious code, making them invisible to standard security tools. According to The Hacker News, the attacks exploited domains that remained accessible in production environments, despite being meant for internal testing only. This allowed attackers to use these domains to trick the AI assistants into processing their requests.
The five browser publishers paid a total of $20,500 to Gal Weizman for identifying and reporting the vulnerabilities. Google and Comet each awarded $7,000, while Microsoft gave $5,000 and Opera gave $900. Anthropic paid the least, $600, for the vulnerability in Claude in Chrome. The disparity in rewards reflects the severity of the vulnerabilities—those that allowed access to sensitive hardware or the file system were considered more critical than those that only bypassed the AI agent.
To protect themselves, users are advised to disable AI assistants on unfamiliar websites and regularly review and remove unnecessary permissions granted to browser extensions. Gal Weizman reported these vulnerabilities to the publishers before making his findings public. As of now, no active exploitation of these flaws has been recorded.
Browser AI Assistants Vulnerable to Extension-Based Attacks
AI-rewritten from original reportingHow it works
browser-securityai-assistantvulnerabilitycybersecurityextension-hackdata-leak
Original sources:
- 🇫🇷Clubic



