The ugly part is not the exploit, it's the trust model
What jumps out to me is how boring the attacker’s foothold is compared with the payoff. A malicious extension is hardly exotic. But once a browser starts delegating real work to an AI assistant, that “just an extension” foothold stops being minor and starts looking like a control plane. That’s the uncomfortable bit here. The extension doesn’t need to “hack the model” in any dramatic sense. It just has to sit where the browser already trusts it, then bend the agent’s inputs and outputs enough to
papoo.work