A browser exploit, sometimes called browser hijacking or a drive-by download, is a form of malicious code that takes advantage of a flaw or vulnerability in an operating system or piece of software with the intent to alter your browser settings without your knowledge.
When there is a weakness in your browser or if browser security is set low, vulnerabilities can be exploited by cybercrooks. For example, ActiveX scripts could install by themselves which can be used to change policies and change a program to make its removal difficult. Users can be tricked into downloading and installing a hijack themselves. Some browser exploits come in the form of an error report that appears to be from the user's own PC. Malicious websites can give instructions to install a particular plug-in to view the site correctly and others make the user believe they are getting a browser enhancement or a system update.
Usually browser exploits don't harm your data or spread themselves through email. But hijacks make your computer vulnerable to other attacks.
Symptoms of a browser hijacking: