Executive Summary
In June 2026, a malicious Chrome extension named "Search for perplexity ai" was discovered impersonating the legitimate Perplexity AI search engine. This extension altered users' default search settings, intercepting all address-bar queries and routing them through attacker-controlled infrastructure before redirecting to legitimate search services. While no credential theft was confirmed, the extension's permissions allowed for extensive data collection, posing significant privacy risks. (bleepingcomputer.com)
This incident underscores the growing trend of cybercriminals exploiting trusted AI brands to distribute malicious software. It highlights the need for enhanced vigilance in verifying browser extensions and the importance of robust security measures to prevent unauthorized data interception.
Why This Matters Now
The rise of AI-themed malicious extensions exploiting trusted brands emphasizes the urgent need for users to verify the authenticity of browser extensions and for developers to implement stricter security measures to prevent unauthorized data interception.
Attack Path Analysis
An attacker published a malicious Chrome extension impersonating Perplexity AI, leading users to install it. The extension gained elevated permissions to intercept and redirect search queries. It monitored and logged all user search inputs, capturing sensitive data. The extension communicated with attacker-controlled servers to transmit collected information. User search data was exfiltrated to external servers without consent. The attack resulted in unauthorized data collection and potential privacy breaches.
Kill Chain Progression
Initial Compromise
Description
An attacker published a malicious Chrome extension impersonating Perplexity AI, leading users to install it.
Related CVEs
CVE-2026-12456
CVSS 4.2A same-origin policy bypass vulnerability in Google Chrome Extensions allows attackers to read or manipulate cross-origin web content, exposing user session data and confidential information.
Affected Products:
Google Chrome – < 149.0.7827.155
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Browser Extensions
Modify Registry
User Execution: Malicious File
Phishing: Spearphishing Attachment
Input Capture: Keylogging
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing system and network security are documented, in use, and known to all affected parties.
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Browser extension malware targeting AI tools poses significant risks to software development workflows, credential theft, and unauthorized access to proprietary code repositories and development environments.
Information Technology/IT
IT infrastructure faces elevated threats from malicious extensions intercepting search traffic, potentially compromising network security monitoring, system administration activities, and sensitive technical documentation access.
Financial Services
Browser-based attacks create compliance risks under PCI DSS requirements, threatening customer data through search interception and potential credential harvesting in financial research and trading platforms.
Health Care / Life Sciences
Extension malware violates HIPAA compliance requirements for encrypted traffic and access controls, risking patient data exposure through compromised medical research and healthcare system administration activities.
Sources
- Fake Perplexity extension on Chrome Web Store tracked searcheshttps://www.bleepingcomputer.com/news/security/fake-perplexity-extension-on-chrome-web-store-tracked-searches/Verified
- Chromium extension uses AI‑related branding to redirect browser searchhttps://www.microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-search/Verified
- Malicious Perplexity-Themed Chrome Extension Hijacked Search Traffichttps://www.mallory.ai/stories/019f1492-7fbc-7549-bab3-01a445177f23Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to intercept and exfiltrate sensitive user data by enforcing strict workload isolation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to deploy and execute malicious code within the cloud environment would likely be constrained, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges within the cloud environment would likely be constrained, limiting unauthorized access to sensitive data.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the cloud environment would likely be constrained, reducing the risk of unauthorized data access.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be constrained, limiting unauthorized external communications.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data to external servers would likely be constrained, reducing the risk of unauthorized data leakage.
The overall impact of unauthorized data collection and privacy breaches would likely be reduced, limiting the scope of the incident.
Impact at a Glance
Affected Business Functions
- Search Engine Operations
- User Data Privacy Management
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of user search queries and browsing behavior.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict browser extensions' access to sensitive data.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic from browser extensions.
- • Utilize Threat Detection & Anomaly Response to identify and respond to unusual extension behaviors.
- • Apply Inline IPS (Suricata) to detect and prevent malicious payloads from being executed.
- • Educate users on verifying the authenticity of browser extensions before installation.



