logo

Chrome Extension Vulnerabilities: Millions at Risk

ID: 0a03f18b-7200-5a55-bea0-8642fe229e1e

STIX ID: report--0a03f18b-7200-5a55-bea0-8642fe229e1e

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Do Son

...
...

Rebora Security Research reports two critical Chrome extension vulnerabilities—MaXSS in MaxAI and Spyder in SiderAI—that allow visiting webpages to send unsanitized messages or synthesize user actions, enabling arbitrary command execution, hidden tab creation, screenshot capture, chat-history theft and data exfiltration; both extensions have broad deployment (millions of installs) and, according to the report, remain unpatched, so users are advised to remove them to prevent account takeover and data leakage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.