Critical Chrome Extension Vulnerabilities Enable Browser Compromise Attacks

Two critical vulnerabilities discovered in popular AI-powered Chrome extensions, SiderAI and MaxAI, could allow attackers to silently compromise browser sessions, steal sensitive data, and execute full account takeovers across any website.

Dubbed “Spyder” and “MaXSS” respectively, both flaws remain unpatched after vendors failed to respond to responsible disclosure attempts.

Rebora Security Research identified the flaws in a new class of browser tools known as agentic side panels, AI-driven extensions that inject code into every website a user visits to deliver summarization, reasoning, and interactive AI capabilities.

Critical Chrome Extension Vulnerabilities

The two affected extensions collectively account for over 10 million installations across Chrome and Edge browsers. SiderAI alone holds 10 million installs and ranks within the Chrome Web Store’s Top 25 Popular Extensions, while MaxAI accounts for an additional 1 million installs.

Agentic side panels operate through two core components: a content script and a background process.

The content script is injected into every webpage the user visits, giving it direct access to what the user sees and interacts with, while the background process serves as the extension’s backend, relaying commands and decisions.

This architecture is designed with a security boundary that prevents webpage JavaScript from interfering with the content script, but both SiderAI and MaxAI failed to enforce that boundary properly.

MaxAI’s content script was designed to relay powerful commands, such as opening new tabs and capturing screenshots, to the background process.

The critical flaw was that the content script accepted these sensitive messages even when they originated from an arbitrary webpage rather than the extension itself and blindly forwarded them to the background.

Researchers demonstrated how an attacker could silently open hidden browser tabs to a victim’s Gmail and Google Calendar to capture screenshots and access ChatGPT and Claude accounts to extract AI memory dumps, all with zero user interaction.

SiderAI’s content script was built to embed arbitrary websites and simulate user gestures such as clicking and typing in order to interact with page content on the user’s behalf.

Rebora Researchers synthesized a malicious event from a seemingly legitimate webpage, triggering this functionality without user consent.

In their proof-of-concept, attackers opened a hidden Gemini session inside the victim’s browser, injected a prompt to dump the AI’s stored memory, clicked “share” to make the conversation public, and exfiltrated the shareable link to the attacker entirely invisible to the victim.

Because both extensions operate with broad browser permissions, the attack surface extends well beyond standard web exploitation.

Attackers could read and exfiltrate emails, documents, cloud drive files, and authentication tokens, send emails or modify documents on behalf of victims, steal session credentials to achieve full account takeover across web services, and in some scenarios, access arbitrary files from the underlying operating system.

For organizations, this represents a complete compromise of internal assets, intellectual property, and employee identities.

Despite following a responsible disclosure process, neither SiderAI nor MaxAI vendors responded. Google’s security team was also notified as the official owner of the Chrome Web Store.

Both extensions remain publicly available in their vulnerable versions. Users are urged to immediately check their installed extensions and remove SiderAI and MaxAI if present.

Organizations should treat browser extension governance as a critical pillar of their endpoint security strategy, especially as AI-driven tools continue to proliferate and require elevated permissions.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories