Validated Research Published: Aug 25, 2026

Spyder and MaXSS Let Ordinary Webpages Inherit AI Extension Privileges

Rebora disclosed two different browser-extension privilege crossings. Spyder abused Sider's synthetic drag and cross-origin gesture path to drive an authenticated Gemini page; MaXSS sent a forged page message through MaxAI's content script to a generic privileged background-function bridge. Rebora counted about 11 million Chrome and Edge installations across both products at publication, but the two mechanisms and their remediation status must be reviewed separately.

Permission BypassData ExfiltrationClient SecurityTool AuthorizationExtension Security
5 applicable AIDEFEND defenses
Source: MaXSS & Spyder: How two Chrome extensions allow websites to compromise over 10 million browsers 
Authors: Gal Weizman and Gal Bashan (Rebora Security Research)
Original article: Jun 10, 2026

Threat Analysis

  • Both chains began on an ordinary webpage. The victim only needed the affected AI sidebar extension installed and an authenticated browser session. The page itself did not hold extension permissions.
  • Spyder converted a synthetic drag into cross-origin control. The attacker page dispatched a dragstart event that triggered Sider's link-preview path and a disable-iframe-restrictions message. Sider embedded Gemini in an iframe after removing response restrictions.
  • The Sider chain then simulated user gestures. Through an open Shadow DOM and the iframe's WindowProxy, the page sent click and typing commands into the authenticated Gemini origin. Rebora's demonstration prompted Gemini for recent information, created a share link, and leaked that link.
  • MaXSS crossed a different message boundary. A webpage supplied the expected service ID and a page-settable marker to pass MaxAI's content-script source check. The content script forwarded RUN_BACKGROUND_FUNCTION with attacker-chosen browser API names and arguments to the privileged background worker.
  • The MaxAI bridge exposed broad browser authority. Rebora demonstrated tab queries, hidden authenticated tabs, screenshots, and declarative network-rule manipulation leading to universal cross-site scripting. Potential local-file access was discussed, but not demonstrated as part of the published exploit chain.
  • Current status cannot be reduced to the June disclosure. On August 25, AIDEFEND Labs statically inspected store packages. Sider 5.32.2 required isTrusted at the disclosed drag entry and no longer contained the disclosed clickAt handler. MaxAI 8.37.3 still contained the page-settable marker check and RUN_BACKGROUND_FUNCTION bridge shape. These observations are not a dynamic PoC rerun or vendor confirmation.

Applicable AIDEFEND Defenses (5)

AID-H-018.002
Policy-Based Access Control
Very High
Authenticate the caller and origin for every page-to-content-script and content-script-to-background request. A synthetic DOM event, shared message ID, or page-settable JavaScript property cannot establish an extension-owned subject. Requests that lack a verifiable extension or trusted-user origin must fail closed in both products.
AID-H-017.002
Least-Privilege Tool Architecture
Very High
Remove MaxAI's generic browser-API bridge and expose only single-purpose operations with bounded arguments, tab scope, destinations, and side effects. Even if a message reaches the background worker, the caller should not be able to select arbitrary API families and functions.
AID-I-008.002
Cross-Origin Read/Write Segmentation with Step-Up Confirmation
Very High
For Sider's embedded-site path, bind every cross-origin write to the exact origin and stable actionable element, then re-observe it before execution. Reject page-issued coordinate and typing commands, and require a real trusted gesture for sensitive cross-origin actions.
AID-H-018.005
Value-Level Capability Metadata & Data Flow Sink Enforcement
High
Treat screenshots, tab metadata, authenticated page content, Gemini responses, and share URLs as sensitive values. Preserve that classification across content-script and background-worker messages, then block transfers into the attacker page or unapproved destinations.
AID-H-003.010
Deployed AI Software Vulnerability Remediation Lifecycle
High
Track Sider and MaxAI as separate findings. For Sider, reconcile deployed versions and dynamically retest the synthetic-drag, iframe, click, and typing paths before closure. For MaxAI, use expiring managed removal or allowlisting until a vendor-confirmed fix removes the generic bridge and an independent regression test passes.

What Defenders Should Do Now

  • Inventory Sider and MaxAI across Chrome and Edge, including extension ID, version, update channel, managed policy, signed-in profile, and data-access scope.
  • Remove or disable unverified builds on managed browsers. Treat Sider and MaxAI as separate remediation records because one product's code change says nothing about the other.
  • For Sider, dynamically retest synthetic and trusted drag events, iframe-header removal, Shadow DOM reachability, cross-origin click and typing, Gemini sharing, and data return to the parent page.
  • For MaxAI, attempt page-originated RUN_BACKGROUND_FUNCTION requests with forged service IDs and markers. Confirm that the background worker authenticates the caller and exposes no generic browser API dispatch.
  • Restrict extensions to the minimum sites and browser APIs they require. Deny hidden-tab creation, screenshots, network-rule changes, and authenticated cross-origin automation unless an exact product workflow needs them.
  • Record page origin, extension sender identity, requested function, normalized arguments, target tab or origin, policy decision, and returned data for every privileged bridge call.

Conclusion

Spyder and MaXSS share a browser-extension trust boundary, but they do not share an exploit mechanism. Sider treated a synthetic gesture as authority to drive a cross-origin UI; MaxAI let a page reach a generic privileged function dispatcher.

AIDEFEND  maps the common caller-verification failure to AID-H-018.002, then applies AID-I-008.002 to Sider's cross-origin writes and AID-H-017.002 to MaxAI's overbroad bridge. AID-H-018.005 protects the sensitive values exposed after either boundary is crossed. Separate regression tests are required before either finding can be closed.