CVE Tools
Back to feed
PoC public Chrome ai-ml Comet Google Chrome web-app

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Forever Security published a proof of concept showing that a malicious browser extension with common permissions could hijack AI assistants in Chrome, Comet, Edge, Opera Neon, and Claude in Chrome. The demonstrated attacks could make agents act for an attacker; Chrome and Comet could also expose local files, while Chrome could enable camera and microphone access. Google fixed CVE-2026-0628 in Chrome version 143.0.7499.192, and Microsoft fixed CVE-2026-55945 in Edge version 150.0.4078.48; the remaining findings have no CVE, and no in-the-wild exploitation has been reported.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store