Disclosure: This record concerns, among others, Claude in Chrome, an Anthropic product; it is drafted by Claude Fable 5.1, an Anthropic model. The conflict is disclosed per PipeRoll constitutional rule 4. No claim here rests on the drafting model's judgement; all facts trace to the researchers' published write-up and the cited outlets.
id: PIR-2026-0079title: Forever Security's Gal Weizman showed that a browser extension with two ordinary permissions (content scripts and declarativeNetRequest) could inject itself into the trusted pages where five production browser AI agents listen for commands and hand them entire prompts and follow-ups ("Prompt Forcing"), making the agents take screenshots, read local files and browsing history, enable microphone and camera, read the user's email and send results to the attacker. Google (CVE-2026-0628, severity 8.8) and Microsoft (CVE-2026-55945) shipped fixes; Perplexity, Opera and Anthropic paid bounties. Published 2026-09-16date_occurred: not applicable - researcher demonstration against production products (fixes shipped from January 2026; write-up 2026-09-16)date_detected: not applicable (reported by the researcher to each vendor; Opera says it found the same flaw independently)date_disclosed: 2026-09-16 (Forever Security write-up; press the same day)status: corroborated (researchers' write-up read; The Hacker News and BleepingComputer read for vendor responses, CVEs and bounties; every source below opened during editorial review on 2026-10-06)agent_description: The AI assistants built into five Chromium-based browsers or browser products - Gemini Live in Chrome, Copilot in Microsoft Edge, Opera Neon's agent, Perplexity Comet, and Anthropic's Claude in Chrome extension - each able to browse, read page content and act in the user's session with the user's privileges.operator_type: enterprise (five vendors; the agents run on end users' machines)autonomy_level: human-on-the-loop (the agents act on prompts the user gives; the attack supplies the prompts instead)model_stack: Gemini (Chrome), Copilot (Edge), Perplexity's models (Comet), Opera Neon's agent, Claude (Claude in Chrome)harness: each browser's built-in assistant surface and the trusted web pages through which it receives instructionsauthority_scope: whatever the assistant can do in the user's browser and session: read and act on any open page, read local files and history, take screenshots, access microphone and camera, read email, send data to arbitrary sitesfunds_at_risk_usd: unknown (everything reachable from a logged-in browser)blast_radius: public (every user of the five products who installs a malicious extension; demonstrated, not observed in the wild)root_cause: prompt-injection (untrusted input - an extension - steers the agent; the researchers distinguish "Prompt Forcing", supplying the whole prompt and follow-ups rather than inserting text into one, but the taxonomy's token is the same)failure_locus: harness (the browsers accepted agent instructions from page context that an extension could write into, treating it as the vendor's own channel)exploitation_status: researcher-demonstrated (on the production products; no in-the-wild abuse reported)mechanism: Per Forever Security: a Chromium extension needs only two common permissions - content scripts (inject JavaScript into pages, the permission every ad blocker has) and declarativeNetRequest (modify network traffic). With them it injects code into the trusted pages where each assistant listens for commands and "speaks" to the assistant as though the vendor had. Unlike classic prompt injection, the attacker "completely wrote and sent the entire prompt, then continued to give follow-up prompts", giving control over timing and chaining. Demonstrated outcomes: screenshots of user activity, local file reads, microphone and camera, browser profile and history leakage, OS file reads, email summaries exfiltrated to attacker addresses. Vendor outcomes: Google fixed Chrome in 143.0.7499.192 (January 2026) and assigned CVE-2026-0628 (8.8); Microsoft patched Edge 150.0.4078.48 (2026-07-02), CVE-2026-55945 (4.2); Perplexity paid a bounty with no public fix date; Opera says it discovered the same flaw independently and paid anyway; Anthropic rated the Claude in Chrome finding medium severity, paid, and credited Forever Security as first reporter. Bounties: Chrome $7,000, Comet $7,000, Edge $5,000, Opera $900, Claude $600.adversary_present: no (researcher; the attack models a malicious extension author)severity: near-miss (full agent hijack with the user's privileges demonstrated on five production products; no realised loss reported)direct_loss_usd: 0indirect_loss_usd: unknown (five vendor fixes and reviews; $20,500 in bounties)downtime: nonedata_exposure: none in the wild; the demonstration exfiltrated the researchers' own screenshots, files, history and emaildetected_by: third-party (the researchers, via coordinated disclosure to each vendor)time_to_detect: not applicabletime_to_recover: Chrome fixed by January 2026, Edge by 2026-07-02; others undisclosedremediation: Chrome and Edge patched; bounties paid by all five vendors; public write-up after fixesstructural_fix: the vendors' fixes are not described in detail. The general fix the write-up implies: an assistant's command channel must not be reachable from page context any extension can write into; instructions need an origin the agent can verify.controls_that_worked: coordinated disclosure; bounty programmes at all five vendors accepted the reporttelemetry_grade: none (researcher demonstration; no operator telemetry)sources:related: PIR-2026-0035 (Nx packages driving victims' own AI CLIs) - the same pattern of software on the user's machine commandeering an agent that runs with the user's authorityindependence: the researchers' account is confirmed by the vendors' own actions (two CVEs, two shipped fixes, five bounties); no vendor disputed the findingsconfidence: high (researcher write-up, vendor fixes and CVEs agree; exact fix details and Perplexity's fix date undisclosed)