Antivirus

OpenAI’s shiny new Atlas browser might have some serious security shortcomings – and it’s not the only one under threat from dangerous spoof attacks

Fake AI sidebars can perfectly imitate real ones to steal secrets, experts warn Malicious extensions need only minimal permissions to cause maximum chaos AI browsers risk turning helpful automation into channels for silent data theft New “agentic” browsers which offer an AI-powered sidebar promise convenience but may widen the window for deceptive attacks, experts have


  • Fake AI sidebars can perfectly imitate real ones to steal secrets, experts warn
  • Malicious extensions need only minimal permissions to cause maximum chaos
  • AI browsers risk turning helpful automation into channels for silent data theft

New “agentic” browsers which offer an AI-powered sidebar promise convenience but may widen the window for deceptive attacks, experts have warned.

Researchers from browser security firm SquareX found a benign-looking extension can overlay a counterfeit sidebar onto the browsing surface, intercept inputs, and return malicious instructions that appear legitimate.

This technique undermines the implicit trust users place in in-browser assistants and makes detection difficult because the overlay mimics standard interaction flows.

You may like

  • ChatGPT Atlas OpenAI’s new Atlas browser may have some extremely concerning security issues, experts warn – here’s what we know
  • Representational image of a hacker Millions of users have fallen victim to malicious browser extensions because of a critical flaw, but things are changing — here’s what you need to know
  • Two hands typing on a laptop keyboard with a warning exclamation mark above it The surveillance browser trap: AI companies are copying Big Tech’s worst privacy mistakes

How the spoofing works in practice

The attack uses extension features to inject JavaScript into web pages, rendering a fake sidebar that sits above the genuine interface and captures user actions.

Reported scenarios include directing users to phishing sites and capturing OAuth tokens through fake file-sharing prompts. It also recommends commands that install remote access backdoors on victims’ devices.

The consequences escalate quickly when these instructions involve account credentials or automated workflows.

Many extensions request broad permissions, such as host access and storage, that are commonly granted to productivity tools, which reduces the value of permission analysis as a detection method.

Conventional antivirus suites and browser permission models were not designed to recognize a deceptive overlay that never modifies the browser code itself.

As more vendors integrate sidebars across major browser families, the collective attack surface expands and becomes harder to secure.

Users should treat in-browser AI assistants as experimental features and avoid handling sensitive data or authorizing account linkages through them, because doing so can greatly raise the risk of compromise.

You may like

  • ChatGPT Atlas OpenAI’s new Atlas browser may have some extremely concerning security issues, experts warn – here’s what we know
  • Representational image of a hacker Millions of users have fallen victim to malicious browser extensions because of a critical flaw, but things are changing — here’s what you need to know
  • Two hands typing on a laptop keyboard with a warning exclamation mark above it The surveillance browser trap: AI companies are copying Big Tech’s worst privacy mistakes

Security teams should tighten extension governance, implement stronger endpoint controls, and monitor for abnormal OAuth activity to reduce risk.

The threat also links directly to identity theft when fraudulent interfaces harvest credentials and session tokens with convincing accuracy.

Agentic browsers introduce new convenience while also creating new vectors for social engineering and technical abuse.

Therefore, vendors need to build interface integrity checks, improve extension vetting, and provide clearer guidance about acceptable use.

Until those measures are widely established and audited, users and organizations should remain skeptical about trusting sidebar agents with any tasks involving sensitive accounts.

Security teams and vendors must prioritize practical mitigations, including mandatory code audits for sidebar components and transparent update logs that users and administrators can review regularly.

Via BleepingComputer


Best antivirus software header
The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

➡️ Read our full guide to the best antivirus
1. Best overall:
Bitdefender Total Security
2. Best for families:
Norton 360 with LifeLock
3. Best for mob

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Antivirus

Why There’s Simply No Need For Android Antivirus Apps Anymore

Many Android users install an antivirus app on a new device without thinking twice. In 2026, there are good reasons to skip that step entirely…

Many Android users install an antivirus app on a new device without thinking twice. In 2026, there are good reasons to skip that step entirely…
Read More

Continue Reading
Antivirus

‘People use smartphones more but invest less in their security’: New report claims McAfee and Norton remain the most loved antivirus brands as users ditch lesser-known security products for free tools like Microsoft Defender or Apple Xprotect

Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Most smartphone users rely on built-in security without additional protection Paid antivirus adoption on mobile devices continues to decline steadily A significant share


  • Most smartphone users rely on built-in security without additional protection
  • Paid antivirus adoption on mobile devices continues to decline steadily
  • A significant share of users remains unprotected or unaware of safeguards

Most Americans now use their smartphones more than their computers, but very few spend money to protect those phones from hackers, new research has claimed.

A Cybernews report surveyed over 1,000 American adults, and found only 18% of mobile phone users pay for third-party antivirus software.

Built-in tools like Microsoft Defender and Apple’s XProtect have become the default choice for most people, while McAfee and Norton lead the paid market for the second year in a row.

Latest Videos From

You may like

  • Best antivirus software Best Antivirus Software 2026
  • People using Windows 11 laptops Can Windows 11’s built-in antivirus keep you safe? Microsoft thinks so
  • Norton 36src Premium Norton 360 Premium will protect your devices from AI scams, malware, and identity theft for less than $30

Smartphone owners are skipping extra security protections

Most consumers believe the security features already built into their phones are sufficient for daily use, and see little reason to spend extra money on something they think they already own for free.

Roughly 14% of mobile users say they have no cybersecurity tools installed at all on their devices. Another 16% cannot even name what protections they currently have in place.

On desktop computers, the situation looks very different, with far fewer unprotected machines and much wider adoption of third-party security tools.

Windows Defender and Apple’s native security features now serve as the primary defense for 53% of computer users and 51% of mobile users.

Most people choose these free options because they trust the operating system vendor to provide adequate baseline protection.

Paid antivirus adoption on computers has actually grown by 2% since last year, reaching 41% of users.

On mobile devices, however, third-party antivirus usage has dropped by roughly 10% over the same period, falling from 28% to just 18%.

What to read next

  • Customer at home looking happy because his network is protected by ESET Home Security We all need digital protection and the ESET Home Security Plan is the bees knees
  • A hand holding a mobile phone scans a QR code on a blurry laptop screen. The phone issues a warning that the QR code could be malicious. Microsoft phishing threat report shows 146% surge in quishing
  • Malware attack virus alert , malicious software infection , cyber security awareness training to protect business Time for an upgrade? Report warns outdated operating systems could be the ‘unnecessary risk’ your business forgot about

Mobile users face growing risks

Ransomware attacks targeting smartphones are still less common than those aimed at computers, but the threat landscape is shifting rapidly.

Users who depend solely on the free security tools that came with their phones may be underestimating what modern cybercriminals can do.

Paid subscriptions have gained ground over free alternatives, yet the majority of mobile owners still avoid spending money on dedicated protection.

Cybercrime exposure does influence some users to change their habits, but personal experience is not the main driver of adoption for most people.

Many users employ layered security approach, combining antivirus with VPNs and password managers.

However, the data shows that a large segment of mobile users remain either unprotected or unsure about what safeguards they have.

Established brands like McAfee and Norton continue to benefit from user trust, while lesser-known products struggle to gain acceptance even when their features are comparable.


Google logo on a black background next to text reading

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

Read More

Continue Reading
Antivirus

Surfshark One review: Adequate antivirus protection with caveats

At a glanceExpert’s Rating Pros Clean, extremely simple interface Alternative ID lets you mask your whole identity, not just an email address VPN service is solid Cons Full scans hit PC performance hard Very few settings to adjust Not as many features as similarly priced rivals Our Verdict If VPN coverage is your first priority…

At a glanceExpert’s Rating

Pros

Clean, extremely simple interface

Alternative ID lets you mask your whole identity, not just an email address

VPN service is solid

Cons

Full scans hit PC performance hard

Very few settings to adjust

Not as many features as similarly priced rivals

Our Verdict
If VPN coverage is your first priority…
Read More

Continue Reading
Antivirus

NITDA raises alarm on DeepLoad AI malware attacks, proffers solutions

“Never paste commands from a website into your computer; legitimate software never asks for this. Do not open files named ‘Chrome Setup’ or ‘Firefox Installer’ from USB drives; scan all USB devices with antivirus software before use,” the agency said, warning corporate companies of possible cyber attacks…

“Never paste commands from a website into your computer; legitimate software never asks for this. Do not open files named ‘Chrome Setup’ or ‘Firefox Installer’ from USB drives; scan all USB devices with antivirus software before use,” the agency said, warning corporate companies of possible cyber attacks…
Read More

Continue Reading