Mark RadarMARK RADAR
About
EN
Sign in

AI Browser Extensions Expose Firms to Data Theft, Akamai Warns

1 reports · First detected 2026-08-28 · Last active 2026-08-28

Companies are rapidly adopting generative AI browser extensions and agents to search, summarize and process information inside employees’ web sessions. The convenience broadens the corporate attack surface because tools with access to browsing activity, page content or network connections can potentially expose internal records, customer data and login credentials. Akamai said excessive permissions make these products a growing concern for security teams overseeing enterprise AI use.

Nearly 75% of AI browser extensions reviewed by Akamai requested high or critical levels of access, increasing the risk of sensitive-data leakage and session hijacking. The research also highlighted threats facing AI products including Cursor and Perplexity, such as stolen API keys and prompt-injection attacks. Akamai’s findings underscore the need for companies to restrict extension and agent privileges, approve tools centrally and monitor unusual access patterns.

All Coverage

1 original reports

The Backstory

The history behind this event
Critical Flaws in Popular Chrome AI Extensions Put More Than 10 Million Users at Risk2026-06-23 · 1 reports · similarity 0.81

SiderAI and MaxAI are Chrome extensions that integrate generative AI features and have recorded more than 10 million installations. Such tools typically have access to webpage content, account status and user input. A permissions vulnerability could therefore expose work emails, login credentials and private AI conversations, extending the risk well beyond browsing histories.

Cybersecurity company Rebora recently disclosed critical vulnerabilities in SiderAI and MaxAI that attackers could exploit through malicious websites to steal sensitive data, including account credentials, emails and AI conversation histories. At the time of disclosure, neither developer had responded publicly or provided a patch timetable. Rebora also reported details of the vulnerabilities to Google.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)