CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Chromium extension uses AI‑related branding to redirect browser search

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 328

As cited

Copy frozen at (site build).

threat intel

Chromium extension uses AI‑related branding to redirect browser search

Microsoft Threat Intelligence identified a malicious Chromium extension that impersonated Perplexity AI to trick users into installation, with the primary goal of intercepting search queries and collecting browsing data. The extension used Manifest Version 3 capabilities and declarativeNetRequest rules to transparently redirect Omnibox queries through attacker-controlled infrastructure while maintaining the appearance of legitimate search results. Google removed the extension following responsible disclosure, and researchers noted that threat actors increasingly leverage AI-related branding as a social engineering vector to increase campaign success rates.

Why it matters: If your users install this extension, their search queries and typed characters are intercepted and sent to attacker infrastructure, enabling profiling, advertising targeting, or downstream data misuse with elevated privacy risk.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Chromium extension uses AI‑related branding to redirect browser search

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Chromium extension uses AI‑related branding to redirect browser search

Microsoft Threat Intelligence identified a malicious Chromium extension that impersonates the Artificial Intelligence (AI)‑powered answer engine Perplexity AI to hijack browser search traffic. The extension, using Manifest Version 3 (MV3) and declarativeNetRequest (DNR) rules, forwards full queries and real‑time suggestions to an attacker‑controlled domain (perplexity-ai[.]online) before sending users to legitimate search providers, enabling data collection without obvious redirection. Google has removed the extension from its store, but the incident shows how threat actors abuse trusted AI branding and privileged extension access to conduct stealthy search interception, prompting organizations to review extension policies and user training.

Why it matters: Organizations that allow Chromium extensions are affected because the extension can silently capture search queries and browsing data, requiring immediate review of extension controls and user awareness.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Chromium extension uses AI‑related branding to redirect browser search

Microsoft Threat Intelligence identified a malicious Chromium extension that impersonates the Artificial Intelligence (AI)‑powered answer engine Perplexity AI to hijack browser search traffic. The extension, using Manifest Version 3 (MV3) and declarativeNetRequest (DNR) rules, forwards full queries and real‑time suggestions to an attacker‑controlled domain (perplexity-ai[.]online) before sending users to legitimate search providers, enabling data collection without obvious redirection. Google has removed the extension from its store, but the incident shows how threat actors abuse trusted AI branding and privileged extension access to conduct stealthy search interception, prompting organizations to review extension policies and user training.

Why it matters: Organizations that allow Chromium extensions are affected because the extension can silently capture search queries and browsing data, requiring immediate review of extension controls and user awareness.

VendorsMicrosoftGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary