CVE-2026-0628
CVSS 8.8 HIGH: insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who… EPSS 7% (93rd percentile).
Vulnerabilities & Exploits · Web App Attack
Forever Security showed a browser extension could commandeer built-in AI assistants across five Chromium-based products: Google Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic’s Claude in Chrome extension. The demonstrations were not in-the-wild attacks, but they proved the same extension-driven pattern reaches more than one vendor’s browser AI.
The trick was to seize the trusted web page the assistant listens to, then use ordinary extension permissions to rewrite that page and its network traffic. Once the extension spoke through that page, the assistant accepted commands as if they came from the vendor, and in some cases it could read files, drive actions, and use the camera or microphone.
That puts the control point on the browser side of the AI, not in the model itself. If your users can install extensions in browser-hosted AI products, the durable exposure is the extension-to-assistant trust path, and patching one product does not settle the cross-product pattern.
2 sources · 6h ago
CVSS 8.8 HIGH: insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who… EPSS 7% (93rd percentile).
CVSS 4.2 MEDIUM: concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge… EPSS 0.2% (8th percentile). Microsoft patch: Release Notes.
Dark Reading
BragJack Attack Can Turn a Browser's Agentic AI Against It
A new type of attack hijacks AI assistants built directly into a browser to access sensitive information, execute malicious actions, and exfiltrate data.
originalThe Hacker News
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Researchers showed one browser extension could hijack AI features in five Chromium products; some demos could access files, sensors, and browser data.
originalPart of the PlainSec briefing for 2026-09-16
Every edition of this story: Browser Extensions Broke the AI Trust Boundary