Threat reportVulnerabilityTL-2026-0870
Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension Message-Validation Flaws Enable Zero-Interaction Browser Session Compromise Across 11M+ Installs
Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension (TL-2026-0870), also tracked as Spyder, is a critical-severity software vulnerability, first published 2026-06-19. It has no confirmed attribution, affects Sider.AI Sider: ChatGPT Sidebar + AI Tools (SiderAI Chrome/Edge, maps to 15 MITRE ATT&CK techniques (T1005, T1059.007, T1068), and is covered by 9 detection rules and 16 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0870
- Threat ID
- TL-2026-0870
- Also known as
- Spyder, MaXSS, MaXSS & Spyder
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, all sectors, consumer, enterprise, government
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
How Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension works
Rebora Security disclosed two critical improper-input-validation flaws in widely deployed AI browser extensions: 'Spyder' in SiderAI (10M+ installs, Chrome Web Store top-25) and 'MaXSS' in MaxAI (1M+ installs). A malicious webpage can drive each extension's content script to relay attacker-controlled messages to its privileged background service worker without origin/sender validation, granting the page the extension's full capabilities with no user interaction beyond visiting the page.
On 19 June 2026 Rebora Security publicly disclosed two critical vulnerabilities — codenamed 'Spyder' (SiderAI) and 'MaXSS' (MaxAI) — in two AI assistant browser extensions distributed on both Chrome and Edge. The extensions are jointly installed on more than 11 million devices (SiderAI ~10,000,000, extension ID difoiogjjojoaoomphldepapgpbgkhkb; MaxAI ~1,000,000, extension ID mhnlakgilnojmhinhkckjpncpbhabphi). SiderAI is listed among the Chrome Web Store's Top 25 Popular Extensions.
The shared root cause is a broken trust boundary at the content-script message-handling layer. In a Manifest V3 extension, content scripts run in the page's DOM and act as a bridge between untrusted web content and the highly privileged background service worker (which holds the extension's host permissions, tabs, scripting, downloads, and cross-origin fetch capabilities). Both extensions failed to validate the origin/sender of inbound messages: their content scripts accepted sensitive messages that originated from the visited webpage (e.g., via window.postMessage or page-injected DOM events) and forwarded them to the background process as if they were trusted internal commands. Per Rebora: 'MaxAI's content-script made the mistake of accepting such sensitive messages even when they were coming from the webpage' and forwarding them to the background, allowing 'arbitrary websites to force the content-script to ask the background to do just about anything the extension can.'
Spyder abuses SiderAI's design feature of embedding arbitrary websites and invoking user gestures inside those embedded sessions. The attacker 'synthesize[s] an artificial event that activated this functionality from the perspective of a benign webpage,' letting the malicious page simulate clicks and keystrokes across embedded web sessions. This lets a page silently open services such as Google Gemini, drive the AI session, and extract private AI conversation data ('dump the AI's memory of the victim') for external exfiltration.
Demonstrated impact across both flaws: opening hidden/background tabs to victim-authenticated services (Gmail, Google Calendar, Gemini), capturing screenshots of those tabs, simulating clicks and keystrokes, reading email, manipulating documents, exfiltrating AI conversation history, and acting on behalf of the user on virtually any website where the victim is authenticated — enabling account takeover. Because the extensions request broad permissions, Rebora notes a potential path to reading files on the underlying operating system. Exploitation requires no interaction beyond visiting the malicious page, making attacks stealthy and highly scalable.
Rebora attempted responsible disclosure to both vendors and received no response; given the severity it disclosed publicly and notified Google's security teams. No CVE IDs or CVSS scores were assigned or published in the source material at disclosure time. There is no evidence of in-the-wild exploitation reported; the issues are demonstrated by the researchers (PoC-level), and the underlying weakness (CWE-20 improper input validation / CWE-346 origin validation error) is a long-recognized browser-extension anti-pattern.
MITRE ATT&CK techniques used in TL-2026-0870
Collection
T1005 Data from Local System; T1113 Screen Capture; T1114.002 Remote Email Collection
Execution
T1059.007 JavaScript; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
Persistence
collection
T1185 Browser Session Hijacking
Initial Access
Discovery
T1217 Browser Information Discovery
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie
Impact
Exfiltration
Affected products and versions in Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension
- Sider.AI — Sider: ChatGPT Sidebar + AI Tools (SiderAI Chrome/Edge extension)
Vulnerable versions: all versions as of 2026-06-19
Fixed in: none confirmed - MaxAI.me — MaxAI.me (MaxAI Chrome/Edge extension)
Vulnerable versions: all versions as of 2026-06-19
Fixed in: none confirmed
Remediation for Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension
Patches
- No vendor patch confirmed at disclosure; track SiderAI and MaxAI Chrome Web Store / Edge Add-ons store updates for a version that adds sender/origin validation
Immediate actions
- Inventory and identify users of SiderAI (extension ID difoiogjjojoaoomphldepapgpbgkhkb) and MaxAI (extension ID mhnlakgilnojmhinhkckjpncpbhabphi) via browser/EDR telemetry
- Uninstall or force-remove both extensions until vendors ship a fix, given vendors were unresponsive and no patch is confirmed
- Use enterprise browser policy (ExtensionInstallBlocklist / ExtensionInstallForcelist) to block the two extension IDs in Chrome and Edge
Workarounds
- Disable the extensions on sensitive accounts/sessions
- Sign out of high-value Google services (Gmail, Calendar, Gemini) when not in active use to limit hidden-tab abuse
- Restrict extensions to specific sites only via Chrome's per-extension site access setting (On click / On specific sites)
Longer-term hardening
- Enforce an extension allow-list and runtime permission review for any extension requesting broad host, tabs, scripting, or downloads permissions
- Adopt a browser-extension risk-management/EDR capability that monitors content-script-to-background messaging and high-privilege extension actions
- Educate users that AI assistant extensions run with cross-site privileges and should be treated as high-risk endpoints
Weaknesses (CWE) in Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension
Timeline of Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension
- Threadlinqs Intelligence ingested the disclosure as TL-2026-0870 and began detection/remediation analysis.
- No vendor patch confirmed; extensions remained available in the Chrome Web Store and Edge Add-ons with the vulnerable behavior.
- No CVE IDs or CVSS scores were assigned or published in the source material at disclosure time.
- Cyber Security News published secondary coverage describing zero-interaction browser compromise via the two extensions.
- Researchers demonstrated that a single malicious webpage could, with no user interaction beyond the visit, abuse the unvalidated content-script-to-background message bridge to capture screenshots, open and read hidden tabs, simulate clicks and keystrokes, read Gmail and Google Calendar, and exfiltrate stored AI conversation history across 11M+ combined installs.
- Rebora Security dubbed the SiderAI content-script message-validation flaw 'Spyder' and the MaxAI counterpart 'MaXSS', characterizing both as improper validation of postMessage/runtime messages forwarded from web page context to the privileged extension background service worker.
- Rebora informed Google's security teams of the issues given the high severity and scale.
- Rebora reported that attempts to contact both vendors (SiderAI and MaxAI) about the vulnerabilities failed and received no response.
- Rebora Security publicly disclosed the 'Spyder' (SiderAI) and 'MaXSS' (MaxAI) Chrome/Edge extension message-validation vulnerabilities affecting 11M+ installs.
Sources cited for Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension
- MaXSS & Spyder: How two Chrome extensions allow websites to compromise over 10 million browsers
- Chrome Extensions' Critical Vulnerabilities Let Attackers Easily Compromise Millions of Browsers
- Rebora — Endpoint Security Reborn for the AI Era (research vendor)
- OWASP Browser Extension Vulnerabilities Cheat Sheet
- Chrome for Developers — Message passing (content script / background trust boundary guidance)
- MITRE ATT&CK — Browser Extensions (T1176)
Detection coverage for TL-2026-0870
As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0870 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.