logo

Critical Chrome Extension Vulnerabilities Enable Browser Compromise Attacks

ID: eb6219a7-2b87-58c4-8ed1-13593738b000

STIX ID: report--eb6219a7-2b87-58c4-8ed1-13593738b000

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Lucas Martin

...
...

Two critical vulnerabilities in popular AI-powered Chrome extensions (SiderAI and MaxAI) — dubbed “Spyder” and “MaXSS” — allow arbitrary webpages to abuse extension content scripts and background processes to open hidden tabs, capture screenshots, simulate user gestures, dump AI memory, and exfiltrate sensitive data. Proof-of-concept demonstrations show attackers could achieve full account takeover and exfiltrate emails, documents, tokens, and AI conversation links; both extensions remain publicly available and vendors did not respond to responsible disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.