One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
PoC publicChromeCometOur summary
Forever Security published a proof of concept showing that a malicious browser extension with common permissions could hijack AI assistants in Chrome, Comet, Edge, Opera Neon, and Claude in Chrome. The demonstrated attacks could make agents act for an attacker; Chrome and Comet could also expose local files, while Chrome could enable camera and microphone access. Google fixed CVE-2026-0628 in Chrome version 143.0.7499.192, and Microsoft fixed CVE-2026-55945 in Edge version 150.0.4078.48; the remaining findings have no CVE, and no in-the-wild exploitation has been reported.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.