What Happened
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,
Why It Matters
According to the article summary, researchers at Forever Security demonstrated that a single ordinary browser extension could access and effectively hijack built-in AI assistants across multiple Chromium-based products, including Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension, once installed and invoked with a click. This indicates a cross-product weakness where browser extension permissions can be used to control or misuse integrated AI assistants, rather than a flaw in any specific model. From a RealGround perspective, this is primarily an AI supply chain risk: organizations relying on browser-based AI assistants are exposed to extension-level compromise, so they should harden extension policies, maintain an AI-focused SBOM and supply chain inventory, and continuously red team browser-based AI workflows to detect unauthorized control paths through extensions.
RealGround Analysis
This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html
