logo

Chrome Extensions’ Critical Flaws Let Attackers Easily Compromise Millions of Browsers

ID: 2b2fa312-b5da-5ee7-a06a-c9d86dd2c25a

STIX ID: report--2b2fa312-b5da-5ee7-a06a-c9d86dd2c25a

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: Abinaya

...
...

Security researchers at Rebora Security disclosed critical vulnerabilities named “Spyder” and “MaXSS” in AI-powered Chrome extensions SiderAI and MaxAI, installed on over 10 million devices. The flaws arise from improper validation of messages between webpages and extension content scripts, enabling malicious sites to execute privileged actions—open hidden tabs, capture screenshots, simulate clicks/keystrokes, and steal sensitive data including emails, authentication tokens, and private AI conversations—without user interaction; vendors did not respond and the issues were publicly disclosed, with users advised to remove the affected extensions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.