Infoglobez
Live Coverage
Sign in Sign up
Trending: Champions League Transfer News Premier League World Cup
Infoglobez
AI & ML

Malicious Extension Exploits Trust in AI to Hijack Browser Searches

A recently discovered malicious extension disguised as Perplexity AI facilitates search traffic interception, highlighting security risks in AI adoption.

Jun 30, 2026 | 3 min read
Sign in to save

Microsoft researchers uncovered a malicious browser extension imitating the AI-powered search platform Perplexity AI. This extension misled users into installing it while intercepting their search queries and redirecting them through servers controlled by attackers before finally sending them to legitimate search engines. Such deceptive practices open a window into the growing sophistication of cyber threats in the digital space.

According to a blog post from Microsoft Threat Intelligence, the primary aim of this deceptive extension was to siphon off search data and collect browsing information—all while giving users a typical browsing experience to avoid detection. This cunning approach raises serious concerns about privacy as attackers become adept at masquerading their malicious intents under the guise of trusted, popular services.

Once alerted, Microsoft informed Google, prompting the extension's removal. This incident underscores a troubling trend, as researchers noted a rise in attacks leveraging the branding of popular AI tools for phishing and malware initiatives. With AI being such a hot topic right now, it’s almost predictable that cybercriminals would capitalize on its popularity.

Subtle Interception of Searches

This extension didn’t behave like traditional hijackers, which often generate intrusive ads or alter search results. Instead, it functioned with remarkable stealth. By employing Chromium’s Manifest V3 APIs, the attackers could intercept queries entered in the browser's address bar. They rerouted this data through their own infrastructure prior to connecting users with legitimate search tools, rendering their actions almost invisible as users received the expected outcomes. Users were essentially accessing search results while unwittingly handing over sensitive information.

Microsoft highlighted how this setup allowed attackers to monitor search behaviors without raising alarms, enhancing user trust rather than exploiting browser vulnerabilities. This kind of subterfuge points to a broader trend where attackers use legitimate-sounding products to mislead users, making the threat landscape even more complex. It’s not just a matter of enhancing technical prowess; it’s also about understanding human psychology.

“This attack relies heavily on user trust rather than taking advantage of browser security flaws,” explains Vibhum Dubey, an independent cybersecurity expert. It’s become easier for malicious actors to lure users with AI-themed extensions, especially as employees frequently integrate these tools into their workflows. Users typically wouldn’t hesitate to grant extensive permissions to these extensions, misconstruing them as necessary features. This situation has created a fertile ground for misleading apps to thrive.

The Allure of AI Branding

As companies rapidly adopt generative AI technologies, trusted AI brands inadvertently turn into prime targets for attackers. “Cybercriminals are essentially banking on user trust,” notes Sushovan Mukhopadhyay, director analyst at Gartner. “The swift adoption of AI tools presents an attractive opportunity for malicious actors.” This is more significant than it looks; the average user is not equipped with the skills to discern safe from unsafe extensions, especially when they come cloaked in familiar branding.

The risk extends beyond individual users; browser extensions can transform into silent mechanisms that harvest sensitive data related to employee activities, search queries, and business contexts. Companies operating in industries governed by privacy regulations need to tread carefully, as failure to safeguard sensitive data could have disastrous consequences.

Visibility Challenges in Governance

Both Dubey and Mukhopadhyay point out a significant gap in enterprise oversight regarding browser extensions. While most organizations maintain stringent software inventory protocols, few have comparable oversight in managing browser extensions. This oversight gap is troubling, especially considering the ease with which harmful extensions can infiltrate corporate environments.

“Many firms impose strict controls on application use while allowing employees to install browser extensions with minimal scrutiny,” Dubey explains. Instead of focusing just on known malicious extensions, security teams should detect worrisome patterns like alterations to default search settings and permissions requests that overreach the norm. Monitoring these shifts could serve as an early warning system for businesses.

Microsoft echoes this sentiment, recommending that organizations verify extension authors, scrutinize permission requests, and keep an eye on browsers for unauthorized tools. Adopting these practices isn't just about better security—it's about nurturing a culture of awareness where users recognize their roles in the security process.

Mukhopadhyay emphasizes that Chief Information Security Officers (CISOs) should start treating browser extensions like any other critical enterprise software. This requires implementing allowlists, conducting permission audits, and setting up monitoring for unapproved AI applications. If you're working in this space, you'll find that a proactive stance now can save companies from costly breaches later on.

According to Gartner forecasts, by 2029, a significant portion of enterprises will adopt secure browser technologies aimed at bolstering oversight on browser extensions and enhancing risk management efforts. As browsers solidify their role as central hubs for communication and productivity, attackers are likely to intensify their focus on these platforms. This shift means organizations can't afford to become complacent; they need to stay ahead of the curve.

Dubey advocates for approaching browser extensions as “third-party suppliers” requiring comprehensive assessment, approval, and ongoing surveillance akin to other enterprise applications. This perspective reframes the challenge, suggesting that a failure to monitor browser extensions might lead to a gap in security that malicious actors are eager to exploit.

Future Considerations

The implications of this incident extend beyond just immediate remediation. As employee workflows increasingly integrate AI tools, organizations must place heightened emphasis on awareness and education regarding the dangers of seemingly benign browser extensions. Regular training for employees can help them discern safe software from malicious impostors, fostering a more security-conscious culture.

And yet, as we look to the future, strong regulatory frameworks and technological innovations will play a vital role in combating these threats. Companies that prioritize cybersecurity and safeguard their data will not only protect themselves but also maintain trust with their customers. The potential for cybercriminals to exploit such vulnerabilities is real and presents significant challenges that organizations must not overlook.

Source: Christopher Williams · www.csoonline.com
Sign in to join the discussion.