Single Browser Extension Could Hijack AI Assistants Across Chrome, Edge, Opera Neon, Comet, and Claude
Forever Security researchers demonstrate a one-click takeover of built-in AI features in five Chromium-based products, raising concerns about extension permissions and AI security.

Key Takeaways
- A single browser extension can hijack AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome.
- The attack requires user installation of the malicious extension and a single click to take control.
- Potential impacts include prompt injection, data exfiltration, and unauthorized actions.
Related Security News

JadePuffer Agentic AI Attacks Target Azure Tenants, Destroy Cloud Resources
Security researchers have observed the JadePuffer ransomware operator conducting agent-driven attacks against Azure cloud tenants. The attacks involve reconnaissance, credential theft, and the destruction of core cloud components. Details regarding the specific use of agentic AI remain reported but unconfirmed.

Carbonato Botnet Leverages Hermes Agent AI Framework to Compromise Docker Hosts
Security researchers have identified a new botnet campaign, tracked as Carbonato, that repurposes the open-source Hermes Agent AI framework to compromise Docker hosts. The malware leverages exposed container endpoints to execute arbitrary commands through Telegram integration and harvests AI API keys and other sensitive credentials stored on compromised systems.



