Last updated 2 weeks ago
Google's Chrome Web Store hosted a malicious extension impersonating the AI search engine Perplexity, which logged user search queries and address bar input. Microsoft discovered the extension and reported it to Google, who removed it after responsible disclosure. The extension redirected all queries through an attacker-controlled server before showing real results, enabling data exfiltration.
The attack vector was a malicious browser extension that posed as a legitimate AI tool. The extension intercepted every character typed into the address bar and every search query, routing them to an attacker-controlled server. No specific CVE or threat actor was identified, and the data compromised included search queries and address bar input.
Google removed the extension from the Chrome Web Store after Microsoft's responsible disclosure. No further post-incident details such as regulatory actions, litigation, or ransom payments were reported.
Malicious Chrome extension posing as Perplexity AI intercepted search queries and address bar input, routing data through attacker-controlled server.
This incident highlights the risk of malicious browser extensions impersonating popular AI tools, which can intercept sensitive user input. Organizations should enforce strict extension approval policies and monitor for unauthorized extensions that could exfiltrate data. Users should verify extension authenticity and permissions before installation.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector