Browser Extension Security in the Age of AI
Patrick Bushe
June 24, 2024 · 5 min read
AI assistants now live in browser extensions: sidebars that summarize pages, rewrite emails, and answer questions about what you're reading. To do that, many need to read every page you open. That makes extension security more important than it's ever been.
The new risks
- Broad access by design. An AI sidebar that reads "all sites" can see your email, banking pages, and internal work tools, and may send page content to a server for processing.
- Hijacked updates. Attackers target extension developers to push malicious updates to trusted extensions. In late 2024, a phishing attack on the developers of the Cyberhaven extension led to a malicious update that tried to steal session data from users.
- Extensions changing hands. Popular extensions are sometimes sold, and new owners can change what they do.
- Prompt injection. Hidden text on a web page can try to give instructions to an AI assistant that reads it, for example to leak information or take unwanted actions.
- Fake AI extensions that copy popular names to steal accounts or data.
How to use AI extensions safely
- Install from well-known publishers and check the developer, reviews, and privacy policy.
- Limit site access. In Chrome's extension details, set site access to "On click" or "On specific sites" instead of all sites.
- Keep sensitive work separate: use a separate Chrome profile without AI extensions for banking and confidential work.
- Don't let assistants act on untrusted pages without checking what they're about to do.
- Remove extensions you don't use, and review permissions when an update asks for more.
Audit what you have
How to audit your Chrome extensions walks through checking each extension's permissions. For clipboard access, which AI tools often touch, Clipboard Guard asks before any site reads what you've copied.