PHONES Redmi Kids Watch Pro Launches with Offline GPS and Dual Cameras CONSOLES DreamSTer Brings Sega Dreamcast Emulation to MiSTer FPGA DLSS NVIDIA DLSS 5 Update Brings Developer Control Over AI Lighting NINTENDO SWITCH 2 Big Walk Crossplay and Cross-Progression Status Still Unknown GAMES Fortnite Survey Asks if Players Have Played Palworld NINTENDO Nintendo Switch 2 Universal Exploit Found: Works Offline ANDROID ARMSX2 2.6.4 Update Adds Material You Theming to Android PS2 Emulator PHONES Apple iPhone 20 Pro Max Rumored to Get 7-Inch Display GAMES GTA 6 Fans Skip Story for Sandbox Exploration on Launch Day PHONES Apple Foldable Entry to Drive 21% Global Market Growth in 2026 GAMES Neverness to Everness 1.2 Adds Iroi Healer and 999 Nights Mode GAME PERFORMANCE Modern Warfare 4 TTK Faster Than BO7, Slower Than MW2: Beta Data XBOX SERIES X Ghost Recon Wildlands Definitive Edition Adds 4K and 60fps on August 6 NINTENDO Beast of Reincarnation Confirmed for PlayStation, Xbox, PC, and Switch

Microsoft Warns of Fake Perplexity AI Chrome Extension Monitoring Searches

Daniel Cross 0 comments 2 min read

Microsoft warns users about a fake Perplexity AI Chrome extension that monitored search activity and hijacked browser settings before its removal.

Microsoft Perplexity AI
SOFTWARE AND UPDATES

A malicious Chrome extension impersonating Perplexity AI recently slipped through browser store checks to monitor user search activity. This threat matters because it targets a popular AI search tool, potentially exposing sensitive queries to attackers. Microsoft Threat Intelligence identified the rogue software before Google removed it from the Chrome Web Store. Users who installed the extension may have had their typing suggestions and search history logged by the attacker.

Microsoft Threat Intelligence identified the malicious add-on before Google removed it from the store

The fake extension functioned by hijacking browser settings to redirect traffic away from legitimate services. It used chrome_settings_overrides to change the default search engine, routing queries to a server controlled by the threat actors. The extension ID flkebkiofojicogddingbdmcmkpbplcd is the specific marker for this malicious package. Google removed the extension shortly after Microsoft alerted them to the impersonation attempt.

Technical analysis reveals the extension used declarativeNetRequest permissions to log searches and view real-time typing suggestions. This mechanism allowed the attackers to capture data as users typed, even before submitting a search. The extension redirected queries through attacker-controlled servers to intercept the data stream. The domain perplexity-ai.online was used to host the malicious redirection logic.

This incident highlights the risk of third-party browser extensions impersonating legitimate software tools. Users should verify extension IDs and review permissions for any AI-related browser add-ons. Microsoft continues to track these impersonation attempts to protect the broader security ecosystem. The removal of the extension limits current exposure, but vigilance remains necessary for similar threats.

Source: GIZMOCHINA

Discussion

0 comments

Leave a comment