An insufficiently protected internal HTML resource in the Adobe Acrobat extension allowed external websites to read WhatsApp chats, contact lists, and profile information.
Two unpatched vulnerabilities in Claude for Chrome allow data exfiltration from Google services because the activation mechanism does not verify whether user interactions are genuine.
A fake Perplexity extension in Chrome completely redirected user inputs and search queries to an attacker-controlled server before forwarding the requests.
A widely used YouTube ad blocker extension possesses the capability to execute arbitrary JavaScript code, presenting a significant security risk to its large user base.