GMAsia
    AI News·28 Sept 2026·via Fox News

    Malicious browser extensions can hijack AI assistants

    Security researcher Gal Weizman of Forever Security demonstrated how malicious browser extensions can hijack AI assistants. His BragJack research targeted Gemini Live, Perplexity Comet, Microsoft Edge Actions, Opera Neon, and Anthropic's Claude. The attacks required a malicious extension to be installed, but then needed zero additional clicks from the victim. Google paid a $7,000 bounty for a Gemini vulnerability, CVE-2026-0628, which Google has since fixed.

    Nexa's Summary

    The BragJack research shows that even a single malicious browser extension can compromise AI assistants like Gemini and Perplexity Comet. This is not about AI models themselves being inherently insecure. The vulnerability lies in how AI tools interact with browser privileges. The core issue is the privileged component within the browser that executes AI requests, allowing an extension to manipulate network requests and gain unauthorized access.

    Asia's major tech players, including Tencent, Alibaba, and Baidu, are integrating AI into their browsers and services. This research points to a critical security challenge for them. Baidu's Ernie Bot, for example, is deeply embedded in its ecosystem. These companies must secure the interface between their AI models and browser-level actions. Failure to do so risks significant user data exposure and reputational damage.

    The key thing to watch is how quickly Asian browser and AI developers harden these integration points. Google has already patched the Gemini vulnerability, CVE-2026-0628. This sets a precedent for rapid response. The test for Asian firms is whether they can match this speed, especially given the rapid pace of AI adoption in the region. Slow responses will leave users exposed.

    Share this article

    Go deeper
    Original reporting by Fox NewsWe don't republish, read the full story →

    Related reading

    6 stories