# Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension Message-Validation Flaws Enable Zero-Interaction Browser Session Compromise Across 11M+ Installs

> Rebora Security disclosed two critical improper-input-validation flaws in widely deployed AI browser extensions: 'Spyder' in SiderAI (10M+ installs, Chrome Web Store top-25) and 'MaXSS' in MaxAI (1M+ installs). A malicious webpage can drive each extension's content script to relay attacker-controlled messages to its privileged background service worker without origin/sender validation, granting the page the extension's full capabilities with no user interaction beyond visiting the page.

- **Published:** 2026-06-19T00:00:00Z
- **Last reviewed:** 2026-06-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0870
- **ID:** TL-2026-0870
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 19 June 2026 Rebora Security publicly disclosed two critical vulnerabilities — codenamed 'Spyder' (SiderAI) and 'MaXSS' (MaxAI) — in two AI assistant browser extensions distributed on both Chrome and Edge. The extensions are jointly installed on more than 11 million devices (SiderAI ~10,000,000, extension ID difoiogjjojoaoomphldepapgpbgkhkb; MaxAI ~1,000,000, extension ID mhnlakgilnojmhinhkckjpncpbhabphi). SiderAI is listed among the Chrome Web Store's Top 25 Popular Extensions.

The shared root cause is a broken trust boundary at the content-script message-handling layer. In a Manifest V3 extension, content scripts run in the page's DOM and act as a bridge between untrusted web content and the highly privileged background service worker (which holds the extension's host permissions, tabs, scripting, downloads, and cross-origin fetch capabilities). Both extensions failed to validate the origin/sender of inbound messages: their content scripts accepted sensitive messages that originated from the visited webpage (e.g., via window.postMessage or page-injected DOM events) and forwarded them to the background process as if they were trusted internal commands. Per Rebora: 'MaxAI's content-script made the mistake of accepting such sensitive messages even when they were coming from the webpage' and forwarding them to the background, allowing 'arbitrary websites to force the content-script to ask the background to do just about anything the extension can.'

Spyder abuses SiderAI's design feature of embedding arbitrary websites and invoking user gestures inside those embedded sessions. The attacker 'synthesize[s] an artificial event that activated this functionality from the perspective of a benign webpage,' letting the malicious page simulate clicks and keystrokes across embedded web sessions. This lets a page silently open services such as Google Gemini, drive the AI session, and extract private AI conversation data ('dump the AI's memory of the victim') for external exfiltration.

Demonstrated impact across both flaws: opening hidden/background tabs to victim-authenticated services (Gmail, Google Calendar, Gemini), capturing screenshots of those tabs, simulating clicks and keystrokes, reading email, manipulating documents, exfiltrating AI conversation history, and acting on behalf of the user on virtually any website where the victim is authenticated — enabling account takeover. Because the extensions request broad permissions, Rebora notes a potential path to reading files on the underlying operating system. Exploitation requires no interaction beyond visiting the malicious page, making attacks stealthy and highly scalable.

Rebora attempted responsible disclosure to both vendors and received no response; given the severity it disclosed publicly and notified Google's security teams. No CVE IDs or CVSS scores were assigned or published in the source material at disclosure time. There is no evidence of in-the-wild exploitation reported; the issues are demonstrated by the researchers (PoC-level), and the underlying weakness (CWE-20 improper input validation / CWE-346 origin validation error) is a long-recognized browser-extension anti-pattern.

## MITRE ATT&CK

- T1189 Drive-by Compromise
- T1059.007 JavaScript
- T1203 Exploitation for Client Execution
- T1176 Software Extensions
- T1068 Exploitation for Privilege Escalation
- T1185 Browser Session Hijacking
- T1539 Steal Web Session Cookie
- T1528 Steal Application Access Token
- T1217 Browser Information Discovery
- T1113 Screen Capture
- T1114.002 Remote Email Collection
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1567 Exfiltration Over Web Service
- T1565 Data Manipulation

## Sources

- [MaXSS & Spyder: How two Chrome extensions allow websites to compromise over 10 million browsers](https://rebora.io/blog/spyder-and-maxss-chrome-extension-vulnerabilities-put-millions-at-risk/)
- [Chrome Extensions' Critical Vulnerabilities Let Attackers Easily Compromise Millions of Browsers](https://cybersecuritynews.com/chrome-extensions-critical-vulnerabilities/)
- [Rebora — Endpoint Security Reborn for the AI Era (research vendor)](https://rebora.io/)
- [OWASP Browser Extension Vulnerabilities Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Browser_Extension_Vulnerabilities_Cheat_Sheet.html)
- [Chrome for Developers — Message passing (content script / background trust boundary guidance)](https://developer.chrome.com/docs/extensions/develop/concepts/messaging)
- [MITRE ATT&CK — Browser Extensions (T1176)](https://attack.mitre.org/techniques/T1176/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0870
