One Tiny Extension, Five AI Assistants: The Chrome Hijack Nobody Saw Coming

·
Listen to this article~5 min
One Tiny Extension, Five AI Assistants: The Chrome Hijack Nobody Saw Coming

A single browser extension reportedly took control of AI assistants in Chrome, Comet, Edge, Opera Neon, and Claude. Here's what happened and how to protect yourself.

You know that little browser extension you installed months ago and forgot about? The one that promised to save you five seconds a day? Yeah, that one. It turns out it might be holding the keys to every AI assistant on your machine. Security researchers at Forever Security just dropped a finding that should make anyone who lives in their browser sit up straight. A single, ordinary extension was able to take control of the AI assistants baked into five different Chromium-based products. Not one. Five. ### The Five Products That Got Caught Here's the lineup, and chances are you use at least one of them: - **Gemini Live** inside Google Chrome - **Perplexity Comet**, the AI-first browser - **Microsoft Edge** and its built-in Copilot - **Opera Neon**, Opera's experimental AI browser - **Claude in Chrome**, Anthropic's browser extension The scary part? Once that extension was installed, it could reach into each product's built-in AI with a single click. No pop-up warning. No permission prompt that made you stop and think. Just access. ### Why This Matters More Than It Sounds We've spent years training ourselves to treat browser extensions like harmless little helpers. A coupon finder here, a grammar checker there. But the modern browser isn't just a window to the web anymore. It's where your email lives, your banking happens, your work gets done. And now, increasingly, it's where an AI assistant sits with access to all of it. Think of it like this: you wouldn't hand a stranger the keys to your house just because they offered to water your plants. But that's essentially what's happening when an extension asks for broad permissions and we click "Add to Chrome" without a second thought. "The attack surface isn't the AI itself," one researcher noted. "It's everything sitting between you and the AI." That quote stuck with me. Because it reframes the whole conversation. We keep worrying about whether AI models are safe. Maybe we should be worrying about the plumbing around them. ### What Actually Happened On Comet and Edge, the extension could reportedly interact with the AI assistant directly, feeding it instructions and pulling responses as if it were the user. The same pattern played out across the other three products. One extension, five doors, all unlocked. Forever Security hasn't published every technical detail yet, and that's probably wise. But the takeaway is already clear: the integration between extensions and AI assistants is looser than most of us assumed. ### What You Can Do Right Now - Open your browser's extension manager and actually read what's installed. All of it. - Remove anything you don't recognize or haven't used in the past month. - Check the permissions on the extensions you keep. Does a recipe saver really need to read data on every site you visit? - If you're testing AI browsers like Comet or Neon, treat them like a separate environment. Don't log into your bank there. - Keep your browser updated. Vendors patch fast when findings like this go public. ### The Bigger Picture This isn't a reason to panic and unplug your router. It's a reason to pay attention. The line between "browser feature" and "AI agent with access to your life" is getting blurrier by the quarter, and the security models haven't caught up yet. Antidetect browser users already know this dance. You isolate profiles, you sandbox sessions, you never trust a single layer of defense. Turns out that mindset is about to become mainstream advice for everyone else too. One extension. Five AI assistants. A single click. If that doesn't make you glance at your toolbar, nothing will.