Malicious Extension Spoofs AI Platform to Intercept Searches

A fake Perplexity AI browser extension routed search queries through attacker-controlled servers. It's a visibility problem enterprises haven't solved.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Malicious Extension Spoofs AI Platform to Intercept Searches
Share

Key points

  • Google removed a browser extension that impersonated Perplexity AI to intercept users' search traffic.
  • The extension used Chromium's Manifest V3 APIs to silently reroute queries through attacker-controlled servers before delivering normal results.
  • The attack required no browser exploit; user trust was the entry point.
  • Gartner expects 30% of enterprises to adopt secure browser technologies for extension auditing by 2029.
  • Most organizations audit installed software rigorously but apply almost no oversight to browser extensions.

How did the extension avoid detection?

Because users received the search results they expected, nothing looked wrong. Google removed the extension after Microsoft Threat Intelligence reported it. Microsoft's researchers found it was intercepting address-bar queries and sending them through intermediary infrastructure before forwarding the request to legitimate search engines, collecting browsing data throughout. "Based on our observation of the extension's behavior, we assess its primary objective to be search traffic interception and data collection, which might enable downstream use cases such as profiling, targeted advertising, or other forms of misuse depending on operator intent," Microsoft's team wrote in a blog post.

The extension didn't exploit a browser flaw. "The user becomes the initial access vector," said Vibhum Dubey, an independent cybersecurity researcher. Workers routinely install AI assistants and productivity tools, and they expect those tools to request broad permissions, which lets malicious permission requests blend in.

Why AI brands make convincing bait

We covered a related impersonation incident on 29 June 2026, when Microsoft researchers flagged a counterfeit Perplexity extension piping omnibox input to an attacker server.

"Attackers are following user trust," said Sushovan Mukhopadhyay, director analyst at Gartner. "As employees adopt AI tools quickly, trusted AI brands become high-value bait for social engineering." Extensions can quietly become a data-collection layer inside everyday workflows, he said, capturing search queries, browsing activity and business context. The core problem is that enterprise AI adoption is outpacing security governance, and that gap is exactly where attackers operate.

Should you worry about your organization's browser extensions?

Probably, yes. Dubey has seen enterprises maintain strict application allowlists while employees install extensions with no oversight at all. Security teams should watch for behavioral signals: changes to default search providers, requests for access to all websites, or traffic to domains unrelated to a claimed publisher.

Mukhopadhyay's prescription is blunt: treat extensions as governed enterprise software, not personal productivity tools. That means allowlists, permission reviews and controls on unapproved AI tools. Gartner data puts 30% of enterprises on track to deploy secure enterprise browser technologies for extension auditing and policy enforcement by 2029.

What should affected users do?

Uninstall the extension immediately. Then audit every other extension in your browser: check who published it, what permissions it holds and whether it's actually necessary. If you're a CISO, that audit belongs on a recurring schedule, not a one-time list.

© 2026 Threat Vectr