Two separate security incidents involving AI-powered Chrome extensions have been reported, highlighting risks to user data. One involved 16 extensions that secretly exfiltrated authorization tokens by intercepting network requests, affecting around 900 users. Another campaign compromised two extensions, masquerading as tools for ChatGPT and DeepSeek, which sent full chat histories to external servers for nearly a million users under the guise of anonymous analytics. A separate architectural vulnerability in Chrome's Gemini panel allowed extensions with basic permissions to inject JavaScript, potentially accessing cameras, microphones, and files without explicit user consent, though this has since been patched. AI
IMPACT Highlights significant risks of data exfiltration and unauthorized access through malicious AI browser extensions, urging users to verify permissions and extension legitimacy.
RANK_REASON The cluster details security vulnerabilities and malicious activities related to AI-powered browser extensions, which falls under the 'tool' category as it pertains to the misuse of software tools.
- ChatGPT
- DeepSeek
- Gal Weitzman
- Gemini
- Chrome
- LayerX Security
- Moshe Siman Tov Bustan
- Or Eshed
- OX Security
- Unit 42
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →