하나의 브라우저 확장 프로그램이 여러 AI 도우미를 장악할 수 있다는 경고가 발표됐다.
Forever Security의 보안 연구자들은 일반적인 브라우저 확장 프로그램이 Chrome, Comet, Edge, Opera Neon, Claude 등 다섯 개의 Chromium 기반 제품의 AI 도우미를 통제할 수 있는 방법을 보여주었다. 이 확장 프로그램이 설치되면 사용자는 단 한 번의 클릭으로 각 제품의 내장 AI에 접근할 수 있다. 이는 보안 취약점이 악용될 수 있는 위험한 상황을 나타내며, 사용자들의 주의가 필요하다.
One browser extension can hijack AI assistants across multiple Chromium-based products.
Security researchers at Forever Security have demonstrated that a regular browser extension could gain control over the AI assistants in five Chromium-based products: Chrome, Comet, Edge, Opera Neon, and Claude. Once the extension is installed, it can access each product's built-in AI with a single click. This highlights a serious security vulnerability that could be exploited, raising concerns for users' safety.