LIVE ALERT
⚠️ DailySamchar.in सूचना: सर्वर मैंटेनेंस कार्य 11 तारीख को दोपहर 2:00 PM से 3:20 PM तक रहेगा। इस दौरान वेबसाइट बंद रहेगी। असुविधा के लिए खेद है। || Planned Maintenance: Server will be down on 11th Sep from 02:00 PM to 03:20 PM. We apologize for the inconvenience.

Digital Hijack: Malicious Extensions Turn Leading AI Browsers Into Silent Spies

Digital Hijack: Malicious Extensions Turn Leading AI Browsers Into Silent Spies

The rapid integration of artificial intelligence into daily web browsing has ushered in a new era of convenience, but this evolution has also created significant security vulnerabilities. AI assistants are no longer confined to chat windows; they now possess the ability to summarize pages, interpret visual data, and execute commands directly on websites. A recent investigation by security researcher Gal Weizman of Forever Security has exposed how malicious browser extensions can weaponize these powerful capabilities against unsuspecting users.

The research, dubbed BragJack, highlights a fundamental shift in how browser-based threats operate. By targeting the intersection of AI architecture and browser permissions, researchers identified methods to bypass security protocols in platforms including Gemini in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon, and Anthropic’s Claude.

THE MECHANICS OF AI EXPLOITATION

To understand the threat, one must view browser-based AI systems as having a “brain” and a “body.” The AI serves as the brain, processing information and determining desired actions. The body consists of privileged components within the browser that execute these commands—such as accessing local files, capturing screen data, or interacting with web forms.

The BragJack research demonstrates that if a malicious browser extension can manipulate the communication bridge between these two components, it can essentially highjack the AI’s authority. The attackers primarily utilized the Chromium-based declarativeNetRequest (DNR) system. This system allows extensions to modify network headers and redirect resources, providing a conduit to interfere with content the browser otherwise trusts as safe.

EXPOSING VULNERABILITIES IN LEADING AI TOOLS

The investigation into Google’s Gemini in Chrome revealed a critical flaw that allowed for unauthorized access to sensitive local information. Although Chrome restricted direct script injection, the researchers found that manipulating internal network requests enabled them to bypass these barriers. This breach allowed for the potential acquisition of browser profile data, the activation of hardware like cameras or microphones without user consent, and the capture of screenshots. Google has since issued a patch to mitigate this specific attack vector.

Perplexity Comet presented a more complex scenario involving agent-driven actions. The researchers discovered that by manipulating trust domains, an attacker could force the AI agent to perform tasks, such as summarizing a user’s recent emails and transmitting that data to an external address. Because the AI is designed to act on the user’s behalf, these activities often appear to be legitimate, making them difficult for standard security monitoring tools to detect.

In the case of Microsoft Edge, the vulnerability stemmed from a “race condition”—a timing flaw that allowed an attacker to issue a prompt to the AI before the browser’s internal security checks could fully evaluate the request. This discrepancy enabled the AI to execute commands that would normally be blocked by administrative safeguards.

THE EMERGENCE OF PROMPT FORCING

A central takeaway from the BragJack findings is a technique the researchers call “Prompt Forcing.” Unlike traditional prompt injection, where a malicious instruction is hidden within a webpage, Prompt Forcing allows an attacker to bypass the need for such deception. By utilizing a trusted communication channel within the browser, the attacker can force a command directly into the AI agent.

The primary danger of this approach is its stealth. Traditional malware might exhibit behaviors—such as suspicious file encryption or unexpected network traffic—that trigger security software alerts. Conversely, an AI agent performing actions on a website looks identical to a user browsing the web, effectively hiding the malicious intent behind a veil of legitimate AI activity.

PROTECTIVE MEASURES FOR MODERN BROWSERS

The research emphasizes that, while the vulnerabilities are technical in nature, the solution remains rooted in basic browser hygiene. Browser extensions serve as the initial point of entry for these attacks. If a malicious extension is not installed, the sophisticated techniques described in the study cannot take hold.

Users should regularly audit their installed extensions to remove unused or unrecognized software. It is also critical to exercise caution regarding permissions. An extension that requests broad access to all websites represents a significant security risk, especially when it is not strictly necessary for the tool’s intended function. Furthermore, users should ensure their browsers are fully updated, as developers are actively deploying patches for the specific vulnerabilities identified in this research.

In addition to management, users should consider disabling AI features that they do not actively utilize. Reducing the “attack surface” of a browser—by limiting the number of active, privileged AI agents—minimizes the potential impact should a secondary component be compromised. As AI agents gain deeper access to personal data and browser functionality, the responsibility for maintaining a secure environment shifts toward a combination of robust software architecture and vigilant user behavior. The BragJack findings serve as a stark reminder that as digital assistants become more capable, the safeguards governing their interactions must become equally rigorous.

Disclaimer: This content is auto-generated for informational purposes only.

Source: Read Original News

Leave a Reply

Your email address will not be published. Required fields are marked *