BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AI Browser Extension Intercepted User Searches

Malicious AI extension hijacks browser searches, steals keystrokes from unsuspecting users

  • A malicious Chrome extension impersonating the AI search engine Perplexity intercepted and logged user search queries and keystrokes.
  • According to Microsoft’s Defender research team, the extension routed all data through an attacker-controlled server before redirecting to legitimate results.
  • The malware exploited Chrome’s built-in permissions to set itself as the default search engine and harvest data from the address bar in real-time.
  • This incident is part of a broader trend where malicious actors use popular AI branding to lure victims into installing harmful browser extensions.

Microsoft has revealed a malicious Chrome extension posing as Perplexity that secretly logged all user searches in late June 2026. The extension routed every character typed into the browser’s address bar through a hacker-controlled server.

- Advertisement -

This deceptive add-on, called “Search for perplexity ai,” used a look-alike domain to mimic the legitimate AI search service. Google subsequently removed it from its Web Store following a responsible disclosure.

The extension’s primary function was to intercept searches and collect user data. It leveraged Chrome’s permitted search-provider overrides to set itself as the default search engine.

Consequently, every query was first sent to the attacker’s server, which logged the browser headers, IP address, and user agent. The traffic was then redirected to a genuine search engine like Perplexity, Google, or Bing to appear normal.

Furthermore, the malware also captured live search suggestions from the address bar. This meant every character was stolen as users typed, not just upon submission.

- Advertisement -

Microsoft’s researchers found no evidence of password theft. However, the extension requested intrusive permissions and shipped server-side code designed solely for data collection.

The malware also included disabled rules to potentially target other search engines and had capacity for future WebAssembly code execution. This incident aligns with a persistent wave of malicious extensions exploiting AI hype.

Microsoft’s own prior research linked similar chat-skimming extensions to nearly 900,000 installs. The key difference here was the direct targeting of search data and keystrokes via the browser’s core functionality.

Security teams are advised to restrict extensions to an approved list and monitor for changed search settings. Users should treat AI-branded tools with extra caution and verify the publisher before installing any extension.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Saylor’s MicroStrategy to Sell Bitcoin Amid Crypto Slump

Strategy announced a new program authorizing the sale of up to $1.25 billion worth...

$3.7B in Stablecoins Frozen by Censorship

Tether and Circle have frozen approximately $3.7 billion in stablecoins on the Ethereum and...

Russian APT’s 2025 Onslaught: Malware Evolves Against Ukraine

The Russian-linked Gamaredon APT group executed 35 spear-phishing campaigns in 2025, primarily targeting Ukrainian...

Bernstein Sees Entry Point As Nvidia Stock Hits $190

Analysts at Bernstein have reiterated a 'buy' rating for NVIDIA stock, suggesting the current...

Bitcoin ETF Outflows Hit Record as Strategy Fights mNAV

Bitcoin is poised for its steepest monthly loss since June 2022 as investors flee...

Must Read

12 Hosting Providers To Buy VPS With Bitcoin: An Expert Guide for 2026

You need a VPS. You want to pay with Bitcoin. Simple enough, right?Not quite. The market for crypto VPS = VPS hosting that accepts...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading