Security researcher Gal Weizman of Forever Security disclosed on September 16, 2026 that a single malicious browser extension could hijack the built-in AI assistants across five Chromium-based products: Google’s Gemini Live in Chrome, Perplexity’s Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension. Depending on the product, the technique could let an attacker drive the AI agent to act on their behalf, read files from the user’s computer, or activate the camera and microphone. The affected vendors issued patches or paid bug bounties totaling more than $20,000 combined; researchers found no evidence the technique had been used in a real-world attack.