Spyder and MaXSS Let Ordinary Webpages Inherit AI Extension Privileges
Rebora disclosed two different browser-extension privilege crossings. Spyder abused Sider's synthetic drag and cross-origin gesture path to drive an authenticated Gemini page; MaXSS sent a forged page message through MaxAI's content script to a generic privileged background-function bridge. Rebora counted about 11 million Chrome and Edge installations across both products at publication, but the two mechanisms and their remediation status must be reviewed separately.
Threat Analysis
- Both chains began on an ordinary webpage. The victim only needed the affected AI sidebar extension installed and an authenticated browser session. The page itself did not hold extension permissions.
- Spyder converted a synthetic drag into cross-origin control. The attacker page dispatched a
dragstartevent that triggered Sider's link-preview path and adisable-iframe-restrictionsmessage. Sider embedded Gemini in an iframe after removing response restrictions. - The Sider chain then simulated user gestures. Through an open Shadow DOM and the iframe's
WindowProxy, the page sent click and typing commands into the authenticated Gemini origin. Rebora's demonstration prompted Gemini for recent information, created a share link, and leaked that link. - MaXSS crossed a different message boundary. A webpage supplied the expected service ID and a page-settable marker to pass MaxAI's content-script source check. The content script forwarded
RUN_BACKGROUND_FUNCTIONwith attacker-chosen browser API names and arguments to the privileged background worker. - The MaxAI bridge exposed broad browser authority. Rebora demonstrated tab queries, hidden authenticated tabs, screenshots, and declarative network-rule manipulation leading to universal cross-site scripting. Potential local-file access was discussed, but not demonstrated as part of the published exploit chain.
- Current status cannot be reduced to the June disclosure. On August 25, AIDEFEND Labs statically inspected store packages. Sider 5.32.2 required
isTrustedat the disclosed drag entry and no longer contained the disclosedclickAthandler. MaxAI 8.37.3 still contained the page-settable marker check andRUN_BACKGROUND_FUNCTIONbridge shape. These observations are not a dynamic PoC rerun or vendor confirmation.
Applicable AIDEFEND Defenses (5)
What Defenders Should Do Now
- Inventory Sider and MaxAI across Chrome and Edge, including extension ID, version, update channel, managed policy, signed-in profile, and data-access scope.
- Remove or disable unverified builds on managed browsers. Treat Sider and MaxAI as separate remediation records because one product's code change says nothing about the other.
- For Sider, dynamically retest synthetic and trusted drag events, iframe-header removal, Shadow DOM reachability, cross-origin click and typing, Gemini sharing, and data return to the parent page.
- For MaxAI, attempt page-originated
RUN_BACKGROUND_FUNCTIONrequests with forged service IDs and markers. Confirm that the background worker authenticates the caller and exposes no generic browser API dispatch. - Restrict extensions to the minimum sites and browser APIs they require. Deny hidden-tab creation, screenshots, network-rule changes, and authenticated cross-origin automation unless an exact product workflow needs them.
- Record page origin, extension sender identity, requested function, normalized arguments, target tab or origin, policy decision, and returned data for every privileged bridge call.
Conclusion
Spyder and MaXSS share a browser-extension trust boundary, but they do not share an exploit mechanism. Sider treated a synthetic gesture as authority to drive a cross-origin UI; MaxAI let a page reach a generic privileged function dispatcher.
AIDEFEND maps the common caller-verification failure to AID-H-018.002, then applies AID-I-008.002 to Sider's cross-origin writes and AID-H-017.002 to MaxAI's overbroad bridge. AID-H-018.005 protects the sensitive values exposed after either boundary is crossed. Separate regression tests are required before either finding can be closed.