AI Browser Hijacking: How Extensions Put Business Data at Risk

Browser Extensions Could Hijack AI Assistants

A browser extension your employee installs could gain access to more than the pages they visit. Researchers have demonstrated how a malicious extension could exploit browser-connected AI assistants to access sensitive information or perform actions on a user’s behalf.

According to The Hacker News, Forever Security demonstrated related weaknesses affecting Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and Claude in Chrome.

These were research demonstrations, with no publicly reported real-world attacks at the time of the article. Each method required a malicious extension to already be installed and running.

What Is the Threat?

AI assistants can help users navigate websites, access information and complete tasks. Those capabilities also make them an attractive target.

The researchers found ways for a malicious extension to impersonate a trusted webpage and send commands to the assistant’s browser-connected components.

The impact varied by product. Demonstrated capabilities included reading local files in Chrome and Comet, accessing Chrome’s camera and microphone, and directing AI agents to take actions in Comet, Edge, Opera Neon and Claude in Chrome. Not every product exposed the same capabilities.

Why Should Your Business Care?

An employee may install an extension for a simple task without realizing how it could interact with other browser features.

When AI assistants have access to business information or can act through signed-in accounts, a compromised extension could put confidential documents, customer information and everyday workflows at risk.

This research highlights why browser extensions and AI tools need to be included in your company’s IT security policies.

What Can You Do?

  • Update browsers and AI extensions. Google’s Chrome fix was included in its January 2026 security update. The supplied report also identifies an Edge fix; remediation details for the other three products were less clear. Use current supported versions.
  • Review installed extensions. Remove anything unnecessary, unfamiliar or no longer maintained.
  • Control new installations. Have your IT team approve extensions and restrict work browsers to an approved list where possible.
  • Review AI access. Check which assistants can access files, connected accounts, cameras and microphones, and limit access to what employees need.
  • Report unexpected activity. Unexplained AI actions, permission requests or browser behaviour should be raised with IT promptly.

Browser security deserves the same attention as the rest of your technology. Britec can help review your business’s IT environment, strengthen security controls and keep systems maintained.

Unsure what’s running in your team’s browsers? Talk to Britec. Britec helps.