SiderAI and MaxAI Chrome Extensions Expose 10 Million Users to Full Browser Compromise
Critical vulnerabilities dubbed Spyder and MaXSS have been discovered in the SiderAI and MaxAI Chrome extensions, which together are installed on over 10 million devices. The flaws allow malicious websites to hijack browser sessions, steal emails and authentication tokens, and exfiltrate AI conversation data — all without any user interaction beyond visiting a webpage. Neither vendor has responded to disclosure; users are advised to remove both extensions immediately.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.