Chrome Extension Vulnerabilities: Millions at Risk
ResearchSiderAIMaxAIOur summary
Rebora Security Research reports critical Chrome extension vulnerabilities affecting SiderAI and MaxAI, with issues tracked as CVE-WATCHTOWER. The defects, named Spyder and MaXSS, let attackers abuse extension content scripts to trigger actions without user interaction, including stealing sensitive data and issuing unauthorized commands. Because these extensions are installed on more than 10,000,000 and 1,000,000+ devices respectively, the flaws significantly increase the risk of large-scale browser compromise.
Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.