AI & ML

Malicious Extension Exploits Trust in AI Brands to Hijack Browser Searches

A deceptive extension mimicking Perplexity AI hijacks search traffic, showcasing security gaps and the increasing risk of AI-branded tools.

Jun 30, 2026 3 min read
Sign in to save

In a troubling development for web security, a malicious browser extension posing as the AI-driven platform Perplexity AI has been identified and removed by Google, following insights from Microsoft researchers. This extension intercepted users’ search queries, rerouting them through servers controlled by attackers before passing them on to legitimate search engines.

Microsoft Threat Intelligence disclosed that the extension's mission was far from benign. It sought to collect user data while disguising the malicious activity as part of a normal browsing experience. “Our analysis indicates this extension manipulates search traffic and gathers sensitive data,” noted a Microsoft blog post on the incident. “Such techniques could facilitate ulterior motives, including user profiling and targeted advertising,” the team warned.

After the alert, Microsoft promptly notified Google, which then took action against the malicious software. This incident is part of a larger trend, with Microsoft highlighting an uptick in cybercriminals exploiting recognizable AI branding to deceive users into installing harmful applications.

Extension's Stealthy Approach

This extension stood out from conventional browser hijackers by avoiding obvious disruptions. It did not modify search results or inundate users with ads. Instead, Microsoft revealed that it exploited Chromium’s Manifest V3 APIs to capture searches initiated in the browser's address bar. Queries were funneled through the attackers’ infrastructure, which allowed them to monitor search behaviors without raising suspicion.

As a result, users saw expected search results, keeping the operation under the radar. “By employing intermediary infrastructure, the operator can monitor search activities while providing an undisturbed browsing experience,” Microsoft’s analysts stated.

Notably, the strategy hinged more on user trust than the exploitation of technical vulnerabilities. “The fact that this doesn't rely on browser flaws is particularly striking. The user unwittingly acts as the entry point,” said Vibhum Dubey, an independent cybersecurity expert. “Employees typically install productivity tools like password managers or AI assistants, which can often seem legitimate, especially when adorned with AI branding.”

The Allure of Trusted AI Brands

With the swift adoption of generative AI tools, familiar AI brands have become prime targets for social engineering. “Attackers are increasingly capitalizing on user trust,” stated Sushovan Mukhopadhyay, a director analyst at Gartner. As employees rapidly integrate AI into their workflows, these trusted platforms morph into valuable bait.

Mukhopadhyay highlighted a significant risk: these extensions can act as covert data collection mechanisms within day-to-day employee activities, compromising sensitive inquiries and browsing contexts.

He emphasized a deeper organizational challenge—enterprise AI initiatives are accelerating beyond the capacity of robust security governance, providing openings for malicious actors to exploit the divide between enthusiastic personnel and structured controls.

Overlooked Governance Issues

Experts assert that the pressing challenge for enterprises lies in visibility. “While many organizations maintain a solid software inventory process, few replicate that level of scrutiny for browser extensions,” Dubey observed. He noted that many firms enforce strict application allowlists even as employees install browser extensions without adequate oversight.

To enhance security, organizations should shift focus from merely identifying known malicious extensions to scrutinizing risky behaviors—such as changes to search provider settings, requests for extensive website access, and communications with unverified domains. Microsoft advocates for thorough verification of extension publishers and careful analysis of permissions requested by these tools.

Mukhopadhyay contends that Chief Information Security Officers should begin viewing browser extensions as regulated enterprise software, as opposed to mere personal productivity tools. “This translates to employing allowlists, monitoring permission requests, overseeing search settings, and imposing controls on unauthorized AI applications,” he remarked. By 2029, Gartner predicts that 30% of enterprises will incorporate secure browser technologies aimed at enhancing extension oversight and compliance.

Given that browsers are morphing into primary spaces for communication, cloud applications, and AI utilities, it's expected that cyber threats will persist in targeting these avenues. Dubey cautions organizations to treat browser extensions as they would any third-party software, ensuring thorough review and ongoing monitoring for these digital interactions.

Source: David Jones · www.csoonline.com

Comments

Sign in to join the discussion.