PoC public Chrome ai-ml Comet Google Chrome web-app
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
CVE Tools coverage
Forever Security published a proof of concept showing that a malicious browser extension with common permissions could hijack AI assistants in Chrome, Comet, Edge, Opera Neon, and Claude in Chrome. The demonstrated attacks could make agents act for an attacker; Chrome and Comet could also expose local files, while Chrome could enable camera and microphone access. Google fixed CVE-2026-0628 in Chrome version 143.0.7499.192, and Microsoft fixed CVE-2026-55945 in Edge version 150.0.4078.48; the remaining findings have no CVE, and no in-the-wild exploitation has been reported.