Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fortinet Patches Critical Auth Bypass in FortiWeb, FortiManager, FortiClient
August 13, 2026
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
August 13, 2026
Beacon CRM confirms full database theft after AWS access key breach
August 13, 2026
Home/CyberSecurity News/Critical Chrome Extension Flaws Expose Millions of Browsers to Attack
CyberSecurity News

Critical Chrome Extension Flaws Expose Millions of Browsers to Attack

Key Takeaways Critical vulnerabilities were discovered in the popular Chrome extensions SiderAI and MaxAI, affecting over 10 million users. The flaws, dubbed “Spyder” and...

Jennifer sherman
Jennifer sherman
June 19, 2026 3 Min Read
60 0

Key Takeaways

  • Critical vulnerabilities were discovered in the popular Chrome extensions SiderAI and MaxAI, affecting over 10 million users.
  • The flaws, dubbed “Spyder” and “MaXSS,” could allow attackers to fully compromise browser sessions, access sensitive data, and execute actions on behalf of the user without interaction.
  • Exploitation requires only visiting a malicious webpage, enabling stealthy and scalable attacks.
  • There is currently no patch from the extension developers, but users are advised to remove the extensions immediately.

Two widely adopted Chrome extensions, SiderAI and MaxAI, have been found to contain critical security vulnerabilities that could expose millions of users to severe risks. These flaws enable attackers to completely compromise browser sessions, potentially gaining unauthorized access to sensitive data across various websites and even local systems.

Table Of Content

  • Key Takeaways
  • Vulnerabilities in Chrome Extensions
  • What You Should Do

Security researchers at Rebora Security identified these vulnerabilities, naming them “Spyder” and “MaXSS.” The affected extensions are AI-powered “agentic side panel” tools designed to enhance browsing with features like AI-driven summaries and automation. Together, they are installed on more than 10 million devices across Chrome-compatible browsers. SiderAI, in particular, ranks among the top 25 extensions on the Chrome Web Store, underscoring the broad scope of potential exposure.

The core of these vulnerabilities lies in the insecure handling of communications between web pages and the extensions’ internal components, specifically their content scripts.

Vulnerabilities in Chrome Extensions

Content scripts in Chrome extensions serve as crucial intermediaries, facilitating communication between websites and an extension’s background processes. While these scripts are designed to enforce strict isolation, both SiderAI and MaxAI failed to adequately validate inputs originating from web pages.

For MaxAI, researchers demonstrated that a malicious website could transmit specially crafted messages to the extension’s content script. This script would then forward these unverified messages to the background process. This lapse in validation allowed attackers to execute privileged actions, such as opening hidden browser tabs, capturing screenshots, and interacting with user accounts. In a proof-of-concept attack, the researchers successfully accessed Gmail and Google Calendar sessions, extracting sensitive information without the user’s knowledge.

Similarly, the Spyder vulnerability within SiderAI permitted attackers to simulate user interactions, including clicks and keystrokes, within embedded web sessions. By exploiting this capability, a malicious site could silently launch services like Google Gemini, extract private AI conversation data, and exfiltrate it. This represents a significant breach of established browser trust boundaries.

The ramifications of these flaws are extensive. Attackers could potentially read emails, steal authentication tokens, manipulate documents, and perform actions on behalf of the user across almost any website. In some scenarios, the permissions granted to these extensions could even extend to accessing local files on the underlying operating system.

A particularly concerning aspect of these vulnerabilities is that successful exploitation requires no user interaction beyond simply visiting a malicious webpage. This makes the attack vector both stealthy and highly scalable, posing a significant threat to a large user base.

Rebora researchers reported their findings to the respective extension vendors, but they did not receive a response. Given the severity of the issues, the findings were publicly disclosed, and Google, as the operator of the Chrome Web Store, was also notified.

This incident highlights the escalating risks associated with AI-integrated browser extensions and underscores how endpoint security is becoming an increasingly critical battleground in the evolving threat landscape.

What You Should Do

  • Immediately check your Chrome-compatible browser for the presence of SiderAI or MaxAI extensions.
  • If either extension is installed, remove it without delay to mitigate potential risks.
  • Exercise caution when installing new browser extensions, particularly those requesting broad permissions.
  • Regularly review the permissions granted to your existing browser extensions and disable or remove any that are not essential or trustworthy.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

CISA Adds Critical LiteSpeed cPanel Plugin Vulnerability to KEV List

Next Post

AutoJack: Malicious Web Page Hijacks AI Agents to Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
North Korean IT Workers Impersonate Employees Using Forged IDs
August 13, 2026
CISA Warns of Critical Windows Ancillary Function Driver Zero-Day Exploited in Attacks
August 13, 2026
Likho Stealer’s New Toolkit Steals Telegram Sessions and Records Conversations
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us