Threat reportVulnerabilityTL-2026-0870

Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension Message-Validation Flaws Enable Zero-Interaction Browser Session Compromise Across 11M+ Installs

criticalACTIVE

Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension (TL-2026-0870), also tracked as Spyder, is a critical-severity software vulnerability, first published 2026-06-19. It has no confirmed attribution, affects Sider.AI Sider: ChatGPT Sidebar + AI Tools (SiderAI Chrome/Edge, maps to 15 MITRE ATT&CK techniques (T1005, T1059.007, T1068), and is covered by 9 detection rules and 16 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0870

Threat ID
TL-2026-0870
Also known as
Spyder, MaXSS, MaXSS & Spyder
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, all sectors, consumer, enterprise, government
Target regions
Global
Detection rules
9
Indicators of compromise
16

How Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension works

Rebora Security disclosed two critical improper-input-validation flaws in widely deployed AI browser extensions: 'Spyder' in SiderAI (10M+ installs, Chrome Web Store top-25) and 'MaXSS' in MaxAI (1M+ installs). A malicious webpage can drive each extension's content script to relay attacker-controlled messages to its privileged background service worker without origin/sender validation, granting the page the extension's full capabilities with no user interaction beyond visiting the page.

On 19 June 2026 Rebora Security publicly disclosed two critical vulnerabilities — codenamed 'Spyder' (SiderAI) and 'MaXSS' (MaxAI) — in two AI assistant browser extensions distributed on both Chrome and Edge. The extensions are jointly installed on more than 11 million devices (SiderAI ~10,000,000, extension ID difoiogjjojoaoomphldepapgpbgkhkb; MaxAI ~1,000,000, extension ID mhnlakgilnojmhinhkckjpncpbhabphi). SiderAI is listed among the Chrome Web Store's Top 25 Popular Extensions.

The shared root cause is a broken trust boundary at the content-script message-handling layer. In a Manifest V3 extension, content scripts run in the page's DOM and act as a bridge between untrusted web content and the highly privileged background service worker (which holds the extension's host permissions, tabs, scripting, downloads, and cross-origin fetch capabilities). Both extensions failed to validate the origin/sender of inbound messages: their content scripts accepted sensitive messages that originated from the visited webpage (e.g., via window.postMessage or page-injected DOM events) and forwarded them to the background process as if they were trusted internal commands. Per Rebora: 'MaxAI's content-script made the mistake of accepting such sensitive messages even when they were coming from the webpage' and forwarding them to the background, allowing 'arbitrary websites to force the content-script to ask the background to do just about anything the extension can.'

Spyder abuses SiderAI's design feature of embedding arbitrary websites and invoking user gestures inside those embedded sessions. The attacker 'synthesize[s] an artificial event that activated this functionality from the perspective of a benign webpage,' letting the malicious page simulate clicks and keystrokes across embedded web sessions. This lets a page silently open services such as Google Gemini, drive the AI session, and extract private AI conversation data ('dump the AI's memory of the victim') for external exfiltration.

Demonstrated impact across both flaws: opening hidden/background tabs to victim-authenticated services (Gmail, Google Calendar, Gemini), capturing screenshots of those tabs, simulating clicks and keystrokes, reading email, manipulating documents, exfiltrating AI conversation history, and acting on behalf of the user on virtually any website where the victim is authenticated — enabling account takeover. Because the extensions request broad permissions, Rebora notes a potential path to reading files on the underlying operating system. Exploitation requires no interaction beyond visiting the malicious page, making attacks stealthy and highly scalable.

Rebora attempted responsible disclosure to both vendors and received no response; given the severity it disclosed publicly and notified Google's security teams. No CVE IDs or CVSS scores were assigned or published in the source material at disclosure time. There is no evidence of in-the-wild exploitation reported; the issues are demonstrated by the researchers (PoC-level), and the underlying weakness (CWE-20 improper input validation / CWE-346 origin validation error) is a long-recognized browser-extension anti-pattern.

MITRE ATT&CK techniques used in TL-2026-0870

Collection

T1005 Data from Local System; T1113 Screen Capture; T1114.002 Remote Email Collection

Execution

T1059.007 JavaScript; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Web Protocols

Persistence

T1176 Software Extensions

collection

T1185 Browser Session Hijacking

Initial Access

T1189 Drive-by Compromise

Discovery

T1217 Browser Information Discovery

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

Impact

T1565 Data Manipulation

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension

  • Sider.AI — Sider: ChatGPT Sidebar + AI Tools (SiderAI Chrome/Edge extension)
    Vulnerable versions: all versions as of 2026-06-19
    Fixed in: none confirmed
  • MaxAI.me — MaxAI.me (MaxAI Chrome/Edge extension)
    Vulnerable versions: all versions as of 2026-06-19
    Fixed in: none confirmed

Remediation for Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension

Patches

  • No vendor patch confirmed at disclosure; track SiderAI and MaxAI Chrome Web Store / Edge Add-ons store updates for a version that adds sender/origin validation

Immediate actions

  • Inventory and identify users of SiderAI (extension ID difoiogjjojoaoomphldepapgpbgkhkb) and MaxAI (extension ID mhnlakgilnojmhinhkckjpncpbhabphi) via browser/EDR telemetry
  • Uninstall or force-remove both extensions until vendors ship a fix, given vendors were unresponsive and no patch is confirmed
  • Use enterprise browser policy (ExtensionInstallBlocklist / ExtensionInstallForcelist) to block the two extension IDs in Chrome and Edge

Workarounds

  • Disable the extensions on sensitive accounts/sessions
  • Sign out of high-value Google services (Gmail, Calendar, Gemini) when not in active use to limit hidden-tab abuse
  • Restrict extensions to specific sites only via Chrome's per-extension site access setting (On click / On specific sites)

Longer-term hardening

  • Enforce an extension allow-list and runtime permission review for any extension requesting broad host, tabs, scripting, or downloads permissions
  • Adopt a browser-extension risk-management/EDR capability that monitors content-script-to-background messaging and high-privilege extension actions
  • Educate users that AI assistant extensions run with cross-site privileges and should be treated as high-risk endpoints

Weaknesses (CWE) in Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension

CWE-20, CWE-346, CWE-940, CWE-863

Timeline of Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension

  • Threadlinqs Intelligence ingested the disclosure as TL-2026-0870 and began detection/remediation analysis.
  • No vendor patch confirmed; extensions remained available in the Chrome Web Store and Edge Add-ons with the vulnerable behavior.
  • No CVE IDs or CVSS scores were assigned or published in the source material at disclosure time.
  • Cyber Security News published secondary coverage describing zero-interaction browser compromise via the two extensions.
  • Researchers demonstrated that a single malicious webpage could, with no user interaction beyond the visit, abuse the unvalidated content-script-to-background message bridge to capture screenshots, open and read hidden tabs, simulate clicks and keystrokes, read Gmail and Google Calendar, and exfiltrate stored AI conversation history across 11M+ combined installs.
  • Rebora Security dubbed the SiderAI content-script message-validation flaw 'Spyder' and the MaxAI counterpart 'MaXSS', characterizing both as improper validation of postMessage/runtime messages forwarded from web page context to the privileged extension background service worker.
  • Rebora informed Google's security teams of the issues given the high severity and scale.
  • Rebora reported that attempts to contact both vendors (SiderAI and MaxAI) about the vulnerabilities failed and received no response.
  • Rebora Security publicly disclosed the 'Spyder' (SiderAI) and 'MaXSS' (MaxAI) Chrome/Edge extension message-validation vulnerabilities affecting 11M+ installs.

Sources cited for Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension

Detection coverage for TL-2026-0870

As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0870 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats