GAMES Baldur’s Gate 3 Stream Cut After Nude Scene; Cancellation Rumors Spread GAMES GTA 6 Extended Look Premieres on Netflix August 27 GAMES EA Sports FC 26 Patch 1.6.6 Fixes Online Matchmaking Errors TABLETS Teclast P30T 2026 Tablet Launches at $90 with 10.1-Inch Display ANDROID HP OmniPad 12 Launches in India with Snapdragon 6 Gen 3 for $514 ACCESSORIES Xbox Storm King Controller Leak: Gears of War Design and $89.99 Price GAMES Call of Duty Warzone Grappling Hooks Removal Confirmed for August XBOX SERIES X Capcom says digital shift won’t hurt sales as consoles drop discs PC HARDWARE Asus ROG Swift OLED PG27UCWM/PG32UCWM Launch: 4K 240Hz, 480Hz at FHD GAMES Fortnite Chapter 7 Season 4 Release Date: Epic Games Update Timeline ACCESSORIES JSAUX Launches Voidjoy Sub-Brand for Handheld and Traditional Controllers HANDHELD GAMING Retroid Pocket Nova Launches With 120Hz 4:3 Screen and 8 Gen 2 Chip LINUX PortMaster July 2026 Roundup Adds Zelda Reimplementation and Star Wars NINTENDO Everdrive-64 Pro Launches With 64DD Support for $169

Microsoft Warns of Fake Perplexity AI Chrome Extension Monitoring Searches

Daniel Cross 0 comments 2 min read

Microsoft warns users about a fake Perplexity AI Chrome extension that monitored search activity and hijacked browser settings before its removal.

Microsoft Perplexity AI
SOFTWARE AND UPDATES

A malicious Chrome extension impersonating Perplexity AI recently slipped through browser store checks to monitor user search activity. This threat matters because it targets a popular AI search tool, potentially exposing sensitive queries to attackers. Microsoft Threat Intelligence identified the rogue software before Google removed it from the Chrome Web Store. Users who installed the extension may have had their typing suggestions and search history logged by the attacker.

Microsoft Threat Intelligence identified the malicious add-on before Google removed it from the store

The fake extension functioned by hijacking browser settings to redirect traffic away from legitimate services. It used chrome_settings_overrides to change the default search engine, routing queries to a server controlled by the threat actors. The extension ID flkebkiofojicogddingbdmcmkpbplcd is the specific marker for this malicious package. Google removed the extension shortly after Microsoft alerted them to the impersonation attempt.

Technical analysis reveals the extension used declarativeNetRequest permissions to log searches and view real-time typing suggestions. This mechanism allowed the attackers to capture data as users typed, even before submitting a search. The extension redirected queries through attacker-controlled servers to intercept the data stream. The domain perplexity-ai.online was used to host the malicious redirection logic.

This incident highlights the risk of third-party browser extensions impersonating legitimate software tools. Users should verify extension IDs and review permissions for any AI-related browser add-ons. Microsoft continues to track these impersonation attempts to protect the broader security ecosystem. The removal of the extension limits current exposure, but vigilance remains necessary for similar threats.

Source: GIZMOCHINA

Discussion

0 comments

Leave a comment