News Alert: SquareX reveals new browser threat — AI sidebars cloned to exploit user trust
好的,我现在需要帮用户总结这篇文章的内容,控制在100个字以内。首先,我得通读全文,抓住主要信息。 文章讲的是SquareX发布了一项关于AI浏览器的新攻击类型的研究,叫做AI Sidebar Spoofing。攻击者利用恶意浏览器扩展,伪装成可信的AI侧边栏界面,诱骗用户执行危险命令,导致凭证窃取、设备劫持和密码泄露。 接下来,我需要提取关键点:攻击类型、手段、影响以及防御建议。然后用简洁的语言把这些点整合起来,确保在100字以内。 要注意不要使用“文章内容总结”这样的开头,直接描述即可。同时要涵盖主要威胁、攻击方式和防御措施。 最后检查字数,确保不超过限制,并且表达清晰准确。 </think> SquareX揭示了一种新型网络攻击——AI侧边栏欺骗攻击。该攻击利用恶意浏览器扩展伪装成可信的AI侧边栏界面,诱骗用户执行危险操作,导致凭证窃取、设备劫持和密码泄露。研究人员指出,此类攻击难以检测且广泛影响主流浏览器及其AI功能。企业需加强动态分析和浏览器安全措施以应对威胁。 2025-10-23 21:56:11 Author: securityboulevard.com(查看原文) 阅读量:2 收藏

PALO ALTO, Calif., Oct.  23, 2025, CyberNewswire: SquareX released critical research exposing a new class of attack targeting AI browsers.

Cruise Con 2025

The AI Sidebar Spoofing attack leverages malicious browser extensions to impersonate trusted AI sidebar interfaces, which is used to trick users into executing dangerous commands that can lead to credential theft, device hijacking, and password exfiltration.

The research demonstrates how attackers can exploit users’ trust in AI browser sidebars – the primary interface through which users interact with AI browsers like Comet, as well as consumer browsers with AI features like Brave and Edge. By creating pixel-perfect replicas of legitimate AI sidebars, malicious extensions return AI-generated responses that include harmful instructions that unsuspecting users follow.

Ramachandran

“AI has become an essential tool for millions of users to learn new skills and complete tasks. Unfortunately, this has created a dangerous dynamic where people blindly follow AI-generated instructions without the expertise to identify security risks,” explains Vivek Ramachandran, Founder and CEO of SquareX. “With no visual or workflow difference, the AI Sidebar Spoofing attack exploits the trust users place on these AI interfaces, tricking them into performing malicious tasks that they may not fully understand or are aware of.”

SquareX illustrates the AI Sidebar Spoofing attacks with three main case studies, but warns that we will likely see many variants of the attack develop. In one example, the user asks the AI sidebar how to withdraw cryptocurrency from their account. The fake AI Sidebar returns what looks like legitimate instructions but replaces the Binance login page URL with a phishing link.

Thinking it was instructions generated by Comet, the user enters their credentials in the phishing site, which the attacker then uses to login to the victim’s account to access their cryptocurrency. In other examples, users were given false instructions to execute malicious commands that allowed attackers to exfiltrate passwords and hijack their device and execute ransomware attacks remotely.

The researchers also showed that other AI browsers and consumer browsers implementing AI sidebars like Edge, Firefox and Safari are equally vulnerable to the AI Sidebar Spoofing Attack. This means that even if organizations restrict the use of AI browsers, users are still subject to these attacks as it can be operated on any browser with an AI sidebar.

Surprisingly, these attacks require only basic browser extension permissions, commonly found in popular extensions like Grammarly and password managers, making them difficult to detect by simply looking at permission analysis. In fact, the AI Sidebar Spoofing extension can remain dormant, providing legitimate responses, until they see an opportunity to trick users into doing something malicious based on their prompt. Thus, it is absolutely critical that enterprises have both the ability to perform dynamic analysis on extension behavior at run time, as well as granular browser-native guardrails to warn and block users from following malicious instructions.

For more information, users can refer to the technical blog.

About SquareX: SquareX‘s browser extension turns any browser on any device into an enterprise-grade secure browser, including AI Browsers. SquareX’s industry-first Browser Detection and Response (BDR) solution empowers organizations to proactively defend against browser-native threats including rogue AI agents, Last Mile Reassembly Attacks, malicious extensions and identity attacks. Unlike dedicated enterprise browsers, SquareX seamlessly integrates with users’ existing consumer browsers, delivering security without compromising user experience. More information about SquareX’s research-led innovation at www.sqrx.com.

Media contact: Junice Liew, Head of PR, SquareX, [email protected]

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization.

October 23rd, 2025 | News Alerts | Top Stories

*** This is a Security Bloggers Network syndicated blog from The Last Watchdog authored by cybernewswire. Read the original post at: https://www.lastwatchdog.com/news-alert-squarex-reveals-new-browser-threat-where-ai-sidebars-are-cloned-to-exploit-user-trust/


文章来源: https://securityboulevard.com/2025/10/news-alert-squarex-reveals-new-browser-threat-ai-sidebars-cloned-to-exploit-user-trust/
如有侵权请联系:admin#unsafe.sh