logo

Critical Chrome Extension Vulnerabilities Let Attackers Easily Compromise Browsers

ID: 03142c1b-7732-5571-9434-b1b0ea94a4d5

STIX ID: report--03142c1b-7732-5571-9434-b1b0ea94a4d5

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Divya

...
...

Critical vulnerabilities named “MaXSS” and “Spyder” in AI-powered Chrome extensions SiderAI and MaxAI (over ~10 million installs) allow malicious webpages to abuse insecure content-script/background communication to perform privileged actions—opening hidden tabs, capturing screenshots, simulating interactions, accessing AI accounts, and exfiltrating sensitive data—requiring only that a user visit a crafted page; vendors were unresponsive and Google was notified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.