Critical Chrome Extension Vulnerabilities Let Attackers Easily Compromise Browsers
ID: 03142c1b-7732-5571-9434-b1b0ea94a4d5
STIX ID: report--03142c1b-7732-5571-9434-b1b0ea94a4d5
Feed Name: GBHackers
Threat Score
Critical vulnerabilities named “MaXSS” and “Spyder” in AI-powered Chrome extensions SiderAI and MaxAI (over ~10 million installs) allow malicious webpages to abuse insecure content-script/background communication to perform privileged actions—opening hidden tabs, capturing screenshots, simulating interactions, accessing AI accounts, and exfiltrating sensitive data—requiring only that a user visit a crafted page; vendors were unresponsive and Google was notified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
