Rebora Security Research
aidefend-sf0042
MaXSS: MaxAI Generic Background API Bridge to UXSS
- Edge & Client AI
- Copilot & SaaS
- Data Exfiltration
- Credential & Identity Theft
Rebora's MaXSS research showed that an ordinary webpage could provide MaxAI's expected service ID and a page-settable marker, then pass a RUN_BACKGROUND_FUNCTION request through the content script to the privileged background worker. The demonstrated calls queried tabs, opened hidden authenticated pages, captured screenshots, and changed declarative network rules to reach universal XSS. An August 25 static check found the disclosed marker and bridge shape in MaxAI 8.37.3; this is not a full exploit retest or vendor confirmation.
Mapped threat techniques
AML.T0011.003User Execution: Malicious LinkAML.T0107Exploitation for Defense EvasionAML.T0053AI Agent Tool InvocationAML.T0025Exfiltration via Cyber Means