One Browser Extension Exploited Five AI Assistants, Earned $20K in Bug Bounties
A single browser extension exposed a shared architectural flaw across five AI browser assistants — Gemini in Chrome, Comet, Copilot in Edge, Opera Neon, and Claude in Chrome — earning a researcher $20,000 in bug bounties from Anthropic, Google, Microsoft, and Perplexity. The vulnerability allowed the extension to hijack network requests sent to each assistant's backend, effectively giving it control over agents that can read files, take screenshots, and send emails on a user's behalf. The flaw was not unique to any one product; all five vendors had independently converged on the same weak assumption about trusting unverified requests. Security researchers note this represents a class of vulnerability rather than an isolated bug, made more dangerous because modern AI browser agents operate with far greater system privileges than traditional browser extensions. The findings serve as a warning to developers and enterprise security teams that AI agents embedded in browsers must be threat-modeled as privileged execution surfaces, not merely as chat interfaces.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in