Opening SecureFlowMaXSS: MaxAI Generic Background API Bridge to UXSS
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Rebora Security Research aidefend-sf0042

MaXSS: MaxAI Generic Background API Bridge to UXSS

  • Edge & Client AI
  • Copilot & SaaS
  • Data Exfiltration
  • Credential & Identity Theft

Rebora's MaXSS research showed that an ordinary webpage could provide MaxAI's expected service ID and a page-settable marker, then pass a RUN_BACKGROUND_FUNCTION request through the content script to the privileged background worker. The demonstrated calls queried tabs, opened hidden authenticated pages, captured screenshots, and changed declarative network rules to reach universal XSS. An August 25 static check found the disclosed marker and bridge shape in MaxAI 8.37.3; this is not a full exploit retest or vendor confirmation.

Mapped threat techniques

  • AML.T0011.003 User Execution: Malicious Link
  • AML.T0107 Exploitation for Defense Evasion
  • AML.T0053 AI Agent Tool Invocation
  • AML.T0025 Exfiltration via Cyber Means

Source