CVE Tools

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

The Hacker NewsBy The Hacker News

PoC publicChromeComet

Our summary

Forever Security published a proof of concept showing that a malicious browser extension with common permissions could hijack AI assistants in Chrome, Comet, Edge, Opera Neon, and Claude in Chrome. The demonstrated attacks could make agents act for an attacker; Chrome and Comet could also expose local files, while Chrome could enable camera and microphone access. Google fixed CVE-2026-0628 in Chrome version 143.0.7499.192, and Microsoft fixed CVE-2026-55945 in Edge version 150.0.4078.48; the remaining findings have no CVE, and no in-the-wild exploitation has been reported.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store