Rebora Security disclosed two critical vulnerabilities, Spyder and MaXSS, in the AI browser extensions SiderAI and MaxAI, which are installed on more than 10 million Chrome-compatible browsers. The flaws stem from insecure message handling and unsafe extension-to-webpage interactions, allowing a malicious site to compromise a victim’s browser session with no user action beyond visiting a page. Researchers said the bugs affect the broader Chromium-based browser ecosystem because both extensions are supported across Chrome-like browsers.
The reported impact includes execution of privileged extension actions such as opening hidden tabs, taking screenshots, accessing active Gmail and Google Calendar sessions, simulating clicks and keystrokes, stealing AI chat histories, and leaking shareable links. Rebora Security said MaxAI could be abused to perform arbitrary extension actions, while SiderAI could be manipulated to extract private conversations from services including Google Gemini. The researchers said they notified the vendors and Google, but the vendors had not patched the issues or responded before disclosure, prompting recommendations that users remove the extensions and review other installed browser add-ons for similar risk.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Rebora Security reported the Spyder and MaXSS vulnerabilities affecting the SiderAI and MaxAI browser extensions to the vendors and also notified Google. The report says the vendors did not respond before the public disclosure.
Following disclosure, security experts advised users to review installed browser extensions and remove SiderAI and MaxAI if present. At the time of reporting, the vulnerabilities had not been patched by the vendors.
Rebora Security disclosed two critical vulnerabilities, Spyder and MaXSS, in the AI browser extensions SiderAI and MaxAI, which are installed on more than 10 million devices. The flaws allow malicious websites to abuse insecure extension-to-webpage messaging to perform privileged actions and steal sensitive data with no user interaction beyond visiting a page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcerebora.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.