One Browser Extension Can Hijack the AI Assistants in Chrome, Edge, Comet, Opera Neon and Claude
Forever Security researchers built a proof-of-concept extension that quietly took the wheel of built-in AI helpers across five Chromium browsers.

Key points
- Researchers at Forever Security showed a single browser extension can hijack the AI assistants inside five Chromium-based products.
- The affected products are Gemini Live in Google Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude extension for Chrome.
- Once installed, the extension could talk to each product's built-in AI with one click.
- The attack turns a trusted helper into a tool the attacker controls, without any obvious warning to the user.
A browser add-on you install for one job can quietly commandeer the AI assistant that ships inside your browser. That's the finding from researchers at Forever Security, who built a proof-of-concept extension and pointed it at five popular Chromium-based products.
The list covers Gemini Live inside Google Chrome, Perplexity's Comet browser, Microsoft Edge, Opera Neon, and the Claude extension for Chrome. In each case the researchers' extension could reach the built-in AI helper with a single click after install, according to reporting by The Hacker News.
My read: this is the predictable cost of bolting powerful AI agents into the browser without first sorting out what an extension is allowed to whisper in their ear. Extensions have always been a soft underbelly of the browser. Now they sit next to something that can read your tabs, summarise your email and, in some setups, click things on your behalf. We've been tracking this attack surface since our 5 August story on AI browsers being tricked into stealing data, and the tools researchers are finding keep getting sharper.
What actually happens in this attack?
A user installs a normal-looking extension. Behind the scenes, that extension issues instructions to the browser's built-in AI assistant, the same helper you'd use to summarise a page or draft a reply. The AI runs those instructions as if they came from you.
That matters because these assistants are trusted parts of the browser. They can see what you see. On some of the affected products they can also take actions inside websites you're signed into, which is the whole point of an "agentic" browser assistant.
Which products are affected?
Five, all built on the Chromium engine that also powers Chrome.
| Product | Built-in AI hijacked |
|---|---|
| Google Chrome | Gemini Live |
| Perplexity Comet | Comet assistant |
| Microsoft Edge | Copilot in Edge |
| Opera Neon | Neon AI |
| Chrome + Claude extension | Claude |
Forever Security's demonstration showed the extension could reach each of these assistants once installed. Comet and Edge each exposed slightly different surfaces to an extension sitting alongside them.
Should ordinary users be worried?
Yes, but the fix is boring and effective: be picky about extensions. The attack needs you to install the malicious add-on first. A random website can't trigger it on its own.
A few plain habits help. Install extensions only from developers you have a reason to trust. Remove ones you no longer use. Treat a request for broad permissions as a serious ask, not a checkbox.
If you rely on an AI assistant inside your browser at work, assume for now that anything an extension can see, the assistant can too, and the other way round. That's the working mental model until the browser makers publish clearer rules.
What the browser makers need to fix
The underlying problem is a missing wall. Extensions and built-in AI assistants live in the same browser, and there's no clean, documented boundary saying which extension is allowed to speak to which assistant, or with what visible signal to the user.
Until Google, Microsoft, Opera and Anthropic tighten those rules, expect more proof-of-concept work in this vein. The interesting question isn't whether another researcher repeats the trick. It's which vendor ships a real permission model for AI-to-extension traffic first.



