Pixel Perfect Extension Exploited To Bypass Security Headers and Inject Malicious Scripts

A once-trustworthy browser extension, QuickLens, which was a Google Lens wrapper, has been exploited to execute remote code, bypass security headers, and inject malicious scripts.

This incident serves as a chilling reminder of the risks associated with browser extension security, especially when a legitimate tool is sold to unknown owners who weaponize it for cyberattacks.

Originally, QuickLens allowed users to conduct visual searches with Google Lens on any webpage, with features such as screen capture and area selection.

With over 7,000 users, it gained recognition for its functionality and, at one point, even earned a “featured” badge from Google.

However, a malicious twist occurred after version 5.8 was released on February 17, 2026. After changing hands through the ExtensionHub marketplace, the extension’s new owners introduced several alarming updates, transforming a trusted tool into a platform for cybercriminal activity.

The update added malicious code, removed essential security features, and enabled covert script injections. One key change was the modification of the content-security-policy (CSP) headers through a new declarativeNetRequest rule.

This action enabled malicious scripts to bypass traditional security defenses, such as cross-site scripting (XSS) filters and content security policies, opening the door to remote code execution and data exfiltration.

Pixel Perfect Exploit Enables Injection (Source: annex)
Pixel Perfect Exploit Enables Injection (Source: annex)

A Silent, Persistent Threat

The most insidious feature of the update was its ability to silently inject and execute code on every page the user visited. A clever technique used an image pixel (a 1×1 transparent GIF) to load malicious JavaScript via an onload attribute.

Since the CSP headers were stripped from every response, these payloads could run freely on any website, without being blocked by the browser’s built-in defenses.

This silent attack chain allowed attackers to perform a range of malicious activities, including stealing session tokens, capturing user input, and exfiltrating sensitive data.

The use of a command-and-control (C2) server further amplified the risk, enabling the attacker to issue new instructions to the infected extension at any time.

The key to this exploit’s success lies in its stealthy execution. The malicious code was never part of the extension’s source files. Instead, it was delivered dynamically through local storage, making it difficult for traditional security tools to detect.

Pixel Perfect Exploit Enables Injection (Source: annex)
Pixel Perfect Exploit Enables Injection (Source: annex)

The extension continued to function normally for most users, with the only visible change being a single permission prompt requesting broader access. For 7,000 unsuspecting users, this update represented a quiet but dangerous breach.

A Growing Concern

According to Annex, this incident highlights the inherent vulnerabilities of the browser extension ecosystem.

While users trusted the extension’s legitimate functionality, the attack exploited the extension supply chain, where a legitimate tool was sold to malicious actors who weaponized it with a single update.

Even with permission monitoring, it would have been challenging to detect such a sophisticated, evolving attack.

Pixel Perfect Exploit Enables Injection (Source: annex)
Pixel Perfect Exploit Enables Injection (Source: annex)

As we move towards an increasingly digital world, securing browser extensions becomes paramount.

This breach serves as a stark reminder of the importance of rigorous monitoring, vetting, and real-time analysis of browser extensions in your environment.

For businesses and individuals alike, this attack showcases how a seemingly harmless update can turn a trusted tool into a serious security threat.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories