AI-branded Chromium extension warning: Microsoft details a search-redirect threat

SNACK Quick Summary

  • Microsoft has detailed a malicious AI-branded Chromium extension that imitated Perplexity AI.
  • The risk is not just a bad search result: the extension could route address-bar queries and live suggestion traffic through attacker infrastructure first.
  • Chrome and Edge users should check extension publishers, domains, search-engine changes and high-risk permissions before trusting AI search add-ons.
Microsoft screenshot of the AI search lookalike landing page
Image source: Microsoft Security Blog

Snackgirls editor note

Red: “An AI search label is not proof of trust. Address-bar searches can reveal a lot about daily life.”

AIKO: “The tricky part is the redirect. If the user still lands on a normal search page, the interception can stay invisible.”

Nea: “Before installing an extension, the domain and permissions matter more than the name on the button.”

Microsoft Threat Intelligence has published an analysis of a malicious Chromium-based browser extension that spoofed Perplexity AI branding. It looked like an AI search helper, but its real behavior was to change browser search flow and send search requests through attacker-controlled infrastructure first.

Microsoft screenshot of the malicious extension listing
Image source: Microsoft Security Blog
Microsoft screenshot of the extension manifest search-provider settings
Image source: Microsoft Security Blog
Microsoft screenshot of redirect configuration in the extension
Image source: Microsoft Security Blog
Microsoft screenshot of the extension onboarding page
Image source: Microsoft Security Blog

What Microsoft found

The analyzed extension used the name Search for perplexity ai and the lookalike domain perplexity-ai[.]online. That is close enough to the legitimate perplexity[.]ai service to create user confusion.

After installation, the extension overrode Chromium search-provider settings. A query typed into the address bar could go to the attacker domain first and then redirect to a legitimate search provider. Because the user still sees search results, the first-hop interception is easy to miss.

Why address-bar traffic matters

Microsoft highlighted that the extension did not only handle finished searches. Its suggest_url setting could route real-time suggestion requests while a person was still typing in the Omnibox.

Search boxes often contain health questions, accounts, work terms, finance queries, travel plans and hobbies. That makes a browser extension that controls the address bar a privacy risk beyond ordinary ad redirection.

What users should check

Users should review installed extensions, especially AI search assistants and productivity add-ons. Check whether the publisher, website and domain match the real service before keeping the extension enabled.

It is also worth checking whether the default search engine changed unexpectedly. Microsoft recommends limiting untrusted extension installs, watching for unusual permissions and relying on reputation-based protections such as Microsoft Defender SmartScreen where available.

Sources and checked date: Checked on June 30, 2026 (KST)

Related hashtags
#GameSunakku #DigitalLife #Cybersecurity #BrowserExtension #Privacy

Comments

Leave a comment

Game Sunakku에서 더 알아보기

지금 구독하여 계속 읽고 전체 아카이브에 액세스하세요.

계속 읽기