惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
I
InfoQ
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
Y
Y Combinator Blog
博客园_首页
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
A
About on SuperTechFans
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
C
Check Point Blog
B
Blog RSS Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Engineering at Meta
Engineering at Meta
B
Blog
爱范儿
爱范儿
Stack Overflow Blog
Stack Overflow Blog
aimingoo的专栏
aimingoo的专栏
WordPress大学
WordPress大学
F
Fortinet All Blogs
月光博客
月光博客
GbyAI
GbyAI

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Chrome Extensions' Critical Flaws Let Attackers Easily Co...
Abinaya · 2026-06-19 · via Cyber Security News

Critical security flaws discovered in widely used Chrome extensions SiderAI and MaxAI are putting millions of users at risk, enabling attackers to fully compromise browser sessions and potentially access sensitive data across websites and local systems.

Security researchers at Rebora Security uncovered vulnerabilities dubbed “Spyder” and “MaXSS” affecting AI-powered “agentic side panel” extensions.

These tools, designed to enhance browsing through AI-driven summaries and automation, are installed on more than 10 million devices across Chrome-compatible browsers.

Notably, SiderAI ranks among the top 25 extensions on the Chrome Web Store, highlighting the scale of exposure.

The vulnerabilities stem from insecure handling of communication between web pages and the extension’s internal components, particularly content scripts.

Vulnerabilities in Chrome extensions

In Chrome extensions, content scripts act as intermediaries between websites and the extension’s background processes.

While they are supposed to enforce strict isolation, both SiderAI and MaxAI failed to validate inputs received from web pages properly.

In the case of MaxAI, researchers found that malicious websites could send crafted messages to the extension’s content script, which would then forward them to the background process without proper verification.

This effectively allowed attackers to execute privileged actions such as opening hidden tabs, capturing screenshots, and interacting with user accounts.

In a demonstrated attack scenario, researchers accessed Gmail and Google Calendar sessions and extracted sensitive information without user awareness.

Similarly, the Spyder vulnerability in SiderAI enabled attackers to simulate user interactions such as clicks and keystrokes across embedded web sessions.

By abusing this capability, a malicious site could silently open services like Google Gemini, extract private AI conversation data, and leak it externally. This represents a severe breakdown of browser trust boundaries.

The impact of these flaws is extensive. Attackers could read emails, steal authentication tokens, manipulate documents, and execute actions on behalf of the user across virtually any website.

In some cases, the permissions granted to these extensions could even allow access to local files on the underlying operating system.

One of the most concerning aspects is that exploitation requires no user interaction beyond visiting a malicious webpage. This makes the attack vector both stealthy and highly scalable.

Rebora researchers reported the issues to the extension vendors, but received no response. Due to the severity, the findings were publicly disclosed, and Google, as the operator of the Chrome Web Store, was also notified.

Users are strongly advised to verify whether SiderAI or MaxAI are installed in their browsers and remove them immediately if present.

The incident underscores growing risks associated with AI-integrated browser extensions. It highlights how endpoint security is becoming a critical battleground in the evolving threat landscape.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.