---
schema_version: '1.0'
id: news-20260704-604dfc
url: https://gotosocial.chinng-lab-srv.dev/perplexity-wopian-rue-zhi-chromekuo-zhang-ji-neng-gafa-jue-aijian-suo-bumunibian-cheng-sita-narisumasizha-qi-noshou-kou-toha/
url_hash: 604dfc1068e65b57354e8d3c79b1ad26c6a2aa23814482eb22aeea0470733479
canonical_url: https://gotosocial.chinng-lab-srv.dev/perplexity-wopian-rue-zhi-chromekuo-zhang-ji-neng-gafa-jue-aijian-suo-bumunibian-cheng-sita-narisumasizha-qi-noshou-kou-toha
source: ghost-chinng-lab
category: news/tech
category_raw: AI・テクノロジー
region: JP
tags:
- AI・テクノロジー
- AI検索
- アプリ詐欺
- Microsoft
- Malwarebytes
- 脅威分析
lang: ja
published_at: '2026-07-04T11:12:58Z'
fetched_at: '2026-07-04T12:08:04Z'
updated_at: '2026-07-04T12:08:34Z'
status: published
content_hash: null
summary: Microsoftのセキュリティ研究チームが、AI検索サービスPerplexityになりすましたChrome拡張機能「Search for perplexity
  ai」を発見した。この拡張機能は正規のChromeウェブストア審査を通過して公開されており、chrome_settings_overridesとdeclarativeNetRequestという正規権限を組み合わせ、ユーザーのアドレスバー入力や検索クエリをタイポスクワッティングドメイン経由で外部サーバーに送信した後、本物の検索結果へリダイレクトする二段階の手口で発覚を遅らせていた。個々の権限は単体では安全と判定されるため既存の審査プロセスの死角を突いた形であり、Manifest
  V3移行の安全性向上と実際の攻撃耐性のギャップを露呈した。Googleは報告を受け該当拡張機能を削除したが、既にインストール済みの端末からは自動削除されないため手動アンインストールが推奨されている。生成AIブームに便乗したなりすまし詐欺は今後も増加が見込まれ、開発者名・ドメイン・要求権限の確認が自衛策として重要になる。
summary_source: llm
summary_en: Microsoft's security research team discovered the Chrome extension "Search
  for perplexity ai" that became AI search service Perplexity. This extension has
  been published through a regular Chrome web store review,公開 the authoritative authority
  of set settings overrides and declarativeNetRequest to send the user’s address bar
  input and search query to an external server via the typosquatting domain, and then
  delayed the two-stage handset to redirect to the real result. Individual permissions
  are determined to be safe on a stand-alone basis, which is a form of a dead angle
  of the existing review process. The safety of the Manifest V3 migration and the
  gap between actual attack resistance were presented. Google has received a report,
  but it is recommended to uninstall it manually because it is not automatically removed
  from the already installed terminal. In the future, 詐欺ofed scams on the generated
  AI boom are expected to increase, and confirmation of developer name, domain, and
  request authority is important as self-def 。
entities:
- name: Microsoft
  type: organization
- name: Malwarebytes
  type: organization
- name: Perplexity
  type: artifact
- name: Chrome
  type: artifact
key_facts: []
related: []
related_auto:
- name: Alibaba
  type: organization
  weight: 3.0
- name: Copilot
  type: artifact
  weight: 1.0
- name: Aion
  type: artifact
  weight: 1.0
- name: FFロサンゼルス
  type: location
  weight: 1.0
- name: Meta
  type: organization
  weight: 1.0
license_note: full
title: 「Perplexity」を騙る悪質Chrome拡張機能が発覚——AI検索ブームに便乗した"なりすまし詐欺"の手口とは
---

# 「Perplexity」を騙る悪質Chrome拡張機能が発覚——AI検索ブームに便乗した"なりすまし詐欺"の手口とは

## TL;DR
Microsoftのセキュリティ研究チームが、AI検索サービスPerplexityになりすましたChrome拡張機能「Search for perplexity ai」を発見した。この拡張機能は正規のChromeウェブストア審査を通過して公開されており、chrome_settings_overridesとdeclarativeNetRequestという正規権限を組み合わせ、ユーザーのアドレスバー入力や検索クエリをタイポスクワッティングドメイン経由で外部サーバーに送信した後、本物の検索結果へリダイレクトする二段階の手口で発覚を遅らせていた。個々の権限は単体では安全と判定されるため既存の審査プロセスの死角を突いた形であり、Manifest V3移行の安全性向上と実際の攻撃耐性のギャップを露呈した。Googleは報告を受け該当拡張機能を削除したが、既にインストール済みの端末からは自動削除されないため手動アンインストールが推奨されている。生成AIブームに便乗したなりすまし詐欺は今後も増加が見込まれ、開発者名・ドメイン・要求権限の確認が自衛策として重要になる。

## Key Points
- AI・テクノロジー / AI検索 / アプリ詐欺 / Microsoft / Malwarebytes / 脅威分析

## Details
(本文なし。リンク先参照)

## Source
元記事: [「Perplexity」を騙る悪質Chrome拡張機能が発覚——AI検索ブームに便乗した"なりすまし詐欺"の手口とは](https://gotosocial.chinng-lab-srv.dev/perplexity-wopian-rue-zhi-chromekuo-zhang-ji-neng-gafa-jue-aijian-suo-bumunibian-cheng-sita-narisumasizha-qi-noshou-kou-toha/) — published 2026-07-04T11:12:58Z
