logo

AI Sidebar Spoofing Attack: SquareX Uncovers Malicious Extensions that Impersonate AI Browser Sidebars

ID: 9b15cb0a-29bc-5c1f-b172-e11ebec6c564

STIX ID: report--9b15cb0a-29bc-5c1f-b172-e11ebec6c564

Feed Name: HackRead

Threat Score
65/100

Date Published: 2025-10-23

Date Updated: 2026-04-22

Author: CyberNewswire

...
...

SquareX published research demonstrating an "AI Sidebar Spoofing" attack in which malicious browser extensions render pixel-perfect replicas of AI sidebars to return fraudulent AI-generated instructions. By exploiting user trust in AI sidebars across AI-enabled and consumer browsers, attackers can phish credentials, trick users into executing malicious commands, exfiltrate passwords, and enable remote device hijacking or ransomware; the technique requires only common extension permissions and can remain dormant until triggered.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.