Bottom line: A single malicious browser extension can hijack AI assistants in five Chromium-based browsers, compromising user data.
What's happening: The malicious extension, created by a developer, was available on the Chrome Web Store and other marketplaces, and its code was embedded in a JavaScript file injected into browser memory. Forever Security researchers discovered the vulnerability after analyzing the extension's behavior, which allowed it to bypass browser security features and access AI assistants' underlying systems.
What to do: Security teams should immediately review their browser extensions and revoke access for any extension with suspicious activity, and monitor their users for potential data breaches.