The Real Threat Isn't on Your Phone
When we think of app permissions, we picture the pop-ups on our phones asking for access to contacts or location. But security researchers gathering in Las Vegas for Black Hat 2026 are pointing to a far more obscure and potent vulnerability: the permissions granted
to browser extensions and the new wave of AI agents. Unlike a simple on/off toggle in your phone’s settings, these permissions create a layer of “shadow access” inside the very tools you trust most. These add-ons often operate with broad privileges, acting on your behalf within your browser or connected cloud accounts, frequently with little transparency or ongoing oversight. Discussions at the conference have highlighted that attackers increasingly weaponize these extensions to steal data and hijack accounts, often remaining completely invisible to traditional antivirus software.
Your Digital Assistants and Their Baggage
The problem is supercharged by artificial intelligence. AI coding assistants and other agent-like tools are becoming common, with some reports mentioned at Black Hat indicating they are present in over 70% of organizations. These AI agents often operate with the same permissions as a human user, but they work at machine speed, capable of making thousands of automated decisions and API calls in minutes. This creates a massive new attack surface. If an AI tool is compromised or designed with malicious intent, it can abuse its trusted access to read your emails, access your files, or exfiltrate sensitive data without ever triggering a familiar “permission requested” alert. It's a risk based on implicit trust, and it's a blind spot for most users.
Conduct a Browser Extension Audit
The most immediate step you can take is to clean up your web browser, which has become a mini-operating system. Every extension you install is another potential vulnerability. Be ruthless in your audit. On Chrome or Edge: Type `chrome://extensions` or `edge://extensions` into your address bar. Review the list. For each one, ask yourself: Do I use this every single day? Do I remember installing it? Do I implicitly trust its developer with access to my browsing activity? If the answer is no, click “Remove.” Pay special attention to extensions that have permission to “read and change all your data on all websites.” On Firefox: Type `about:addons` into the address bar. Go through the same process. Disable anything you're unsure about, and remove anything you don’t actively need. On Safari: Go to Safari > Settings > Extensions. Disable and then uninstall anything that isn’t essential to your workflow. The security training at Black Hat emphasizes that even extensions from official stores can be risky, as reviews often fail to catch cleverly hidden malicious behavior.
Review Your Connected Cloud Apps
The second front in this battle is your cloud accounts. Many AI tools and third-party services ask for permission to connect to your Google, Microsoft, or Apple account to function. Over time, this creates a web of interconnected permissions that is rarely reviewed. For your Google Account: Go to myaccount.google.com and navigate to the “Security” tab. Find the section named “Your connections to third-party apps & services.” You will likely see a long list of apps you’ve authorized over the years. Click into each one and remove access for any service you no longer use or recognize. For your Microsoft Account: Go to account.microsoft.com/privacy and find the privacy dashboard. Under “Apps and services,” you can see which ones can access your data. Revoke permissions for any that are unnecessary. This is the modern equivalent of checking app permissions, and it's just as critical.















