PulseAugur
EN
LIVE 13:29:39
Русский(RU) Расширение Gemini для Chrome: что оно реально видит и как не поставить подделку

Malicious Chrome extensions steal AI chat data, exploit Gemini panel vulnerability

Two separate security incidents involving AI-powered Chrome extensions have been reported, highlighting risks to user data. One involved 16 extensions that secretly exfiltrated authorization tokens by intercepting network requests, affecting around 900 users. Another campaign compromised two extensions, masquerading as tools for ChatGPT and DeepSeek, which sent full chat histories to external servers for nearly a million users under the guise of anonymous analytics. A separate architectural vulnerability in Chrome's Gemini panel allowed extensions with basic permissions to inject JavaScript, potentially accessing cameras, microphones, and files without explicit user consent, though this has since been patched. AI

IMPACT Highlights significant risks of data exfiltration and unauthorized access through malicious AI browser extensions, urging users to verify permissions and extension legitimacy.

RANK_REASON The cluster details security vulnerabilities and malicious activities related to AI-powered browser extensions, which falls under the 'tool' category as it pertains to the misuse of software tools.

Read on dev.to — LLM tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Malicious Chrome extensions steal AI chat data, exploit Gemini panel vulnerability

COVERAGE [1]

  1. dev.to — LLM tag TIER_1 Русский(RU) · Promptra Team ·

    Gemini for Chrome Extension: What It Actually Sees and How Not to Get a Fake

    <p>Девятьсот тысяч установок и названия со словами ChatGPT и DeepSeek не помешали двум расширениям каждые полчаса отправлять переписку на чужой сервер — разбираемся, какие разрешения запрашивает расширение Gemini или ChatGPT для браузера и как проверить его за пять минут.</p> <p>…