LmCast :: Stay tuned in

BragJack attacks hijack AI browser agents through malicious extensions

Recorded: Sept. 19, 2026, 3:09 p.m.

Original Summarized

BragJack attacks hijack AI browser agents through malicious extensions

News

Featured
Latest

OpenAI details more cases of AI agents taking unauthorized actions

Brevo supply-chain attack injected ClickFix scripts on customer sites

Cisco warns of max severity ISE zero-day exploited in attacks

Microsoft shares workaround for Windows domain login issues

BragJack attacks hijack AI browser agents through malicious extensions

North Korean WaterPlum hackers infected 30,000 devices worldwide

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Get 25 hours of ChatGPT & AI training for just $19.99

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityBragJack attacks hijack AI browser agents through malicious extensions

BragJack attacks hijack AI browser agents through malicious extensions

By Ax Sharma

September 19, 2026
10:56 AM
0

Security researcher Gal Weizman of Forever Security has disclosed a new attack technique that can hijack the AI assistants built into popular browsers using a single malicious browser extension.
Dubbed BragJack, the proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome.
The research earned more than $20,000 in bug bounties from the five vendors, ranging from $600 to $7,000, and produced two CVEs.
The attack requires the malicious extension to already be installed in the victim's browser.
Once it is, the researcher shows the abuse can run without user interaction, letting an extension control an AI browser agent and abuse its existing privileges to access sensitive information or act on the victim's behalf.
Both Google and Microsoft have since resolved the flaws they were assigned.
Abusing trusted browser components
The attacks exploit the way AI assistants are increasingly wired into browsers and handed browser-level capabilities.
In his writeup, Weizman describes these systems as having a "brain" and a "body." The AI model processes instructions and decides what should happen.
A privileged browser component then performs the actions, such as accessing tabs, reading content, taking screenshots, or interacting with websites.
The problem, according to the researcher, is that browser extensions can manipulate web traffic and pages that these privileged components trust.
The same extension was used across all five targets, relying on Chromium's declarativeNetRequest (DNR) functionality. DNR lets extensions modify how network requests are handled, including changing response headers and redirecting resources.
In the Chrome attack, Weizman found that although extensions were blocked from directly touching the privileged chrome://glic component or injecting scripts into Google's Gemini site, DNR rules could still intercept requests made by the embedded Gemini web app.
By weakening security headers and redirecting a JavaScript resource, he executed code inside the Gemini context, communicating directly with Chrome's privileged AI component rather than going through Gemini's normal request flow.
Weizman says the resulting access could read local files, reach web content, take screenshots, and potentially reach the browser's camera and microphone. Chrome assigned the finding CVE-2026-0628 and paid a $7,000 bounty.
From reading data to controlling AI agents
The attacks against agentic browsers such as Perplexity Comet and Opera Neon go further, because their agents can act on websites rather than merely read them.
For Comet, Weizman found the browser's built-in agent extension trusted several Perplexity domains, including a testing domain that did not get the same protections as the primary perplexity.ai site. By removing a redirect to that domain with DNR, he loaded it and injected a content script able to talk to the built-in agent.
The resulting access included browsing history, screenshots, local files, and the ability to send instructions to the agent. Weizman demonstrated forcing the agent to visit Perplexity, summarize the victim's emails, and send the results to another address.
Microsoft Edge presented a different challenge. Microsoft had split its agent into "Think" and "Do" modes to stop it from taking arbitrary instructions and actions at the same time.
Weizman found a race condition that briefly disables the restriction while forcing a prompt, then re-enables the action capability before the agent checks its state. Microsoft assigned CVE-2026-55945 to the race condition.
Similar flaws were demonstrated against Opera Neon and Claude in Chrome, though the latter is itself a browser extension rather than a browser.
Earlier this year, in my work at Manifold Security, I reported a related weakness in Claude for Chrome: the extension ran its built-in AI workflows on synthetic clicks without verifying they came from a real user, and the flagged code was still reproducible eight releases later.
That followed ClaudeBleed, an earlier flaw in the same extension that LayerX disclosed in April, in which Claude for Chrome trusted the claude.ai origin rather than checking which script was actually driving it.
'Prompt Forcing'
Weizman calls the technique used to seize these agents Prompt Forcing.
Unlike conventional prompt injection, where an attacker tries to slip malicious instructions into content an AI is already reading, Prompt Forcing lets the attacker hand the agent an entire prompt and the follow-up instructions. The agent then translates those instructions into legitimate browser actions using its existing privileges.
That matters for endpoint defenses, the researcher argues, because the final action is not carried out by conventional malicious code. Legitimate software is being told to perform the attack.
BragJack points to a growing challenge as browsers and other endpoint apps gain more capable AI agents. A compromised extension that would traditionally see only web content can, in some designs, become a path to software that reads files, browsing data, and acts on websites for the user.
Users should keep browsers fully updated, remove extensions they do not recognize or no longer use, and treat broad "read and change all your data on all websites" permission prompts with caution.
In addition to his writeup, Weizman has published a full technical breakdown covering all five attacks.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Hundreds of fake Chrome VPN extensions route traffic through a proxyMicrosoft Teams will let admins block custom file extensionsTwitch extension with 30K installs exposes users’ OAuth tokensOpenAI admits it didn't disclose rogue AI wiki hijacking incidentGoogle warns of new Chrome zero-day flaw exploited in attacks

Browser
Browser Hijacker
Extensions
Hijack

Ax Sharma
Ax Sharma is a security researcher and journalist focused on malware analyses and cybercrime investigations. His expertise includes open source software security, threat intel analysis, and reverse engineering. Frequently featured by leading media outlets like the BBC, Channel 5 (UK), Fortune, WIRED, among others, Ax is an active community member of the OWASP Foundation and the Canadian Association of Journalists (CAJ).

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Windows 11 KB5124008 update breaks domain trust for some users

Cisco warns of max severity ISE zero-day exploited in attacks

Microsoft shares workaround for Windows domain login issues

Sponsor Posts

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

Overdue a password health-check? Audit your Active Directory for free

Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

A security researcher named Gal Weizman of Forever Security disclosed a novel attack technique termed BragJack, which is capable of hijacking AI browser agents through the use of malicious browser extensions. This research involved testing the technique against five Chromium-based browsers and browser assistants, including Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome, resulting in bug bounties totaling over twenty thousand dollars from the vendors and the creation of two CVEs. The attack is predicated on the malicious extension already being installed in the victim's browser, allowing it to control the AI browser agent and abuse its existing privileges without requiring direct user interaction.

The exploitation targets the design of modern AI systems where an AI model acts as the "brain" processing instructions, and a privileged browser component acts as the "body" executing actions like accessing tabs or reading content. The vulnerability arises because browser extensions can manipulate web traffic and pages that these privileged components implicitly trust. The attacker leveraged the Chromium declarativeNetRequest (DNR) functionality to influence these trusted components. In the Chrome attack, the vulnerability allowed extensions to intercept network requests by weakening security headers and redirecting resources, enabling the execution of code within the Gemini context and direct communication with the privileged AI component rather than adhering to normal request flows. This level of access could lead to reading local files, accessing web content, capturing screenshots, and potentially accessing the browser's camera and microphone, leading to the assignment of CVE-2026-0628 by Microsoft.

The attacks specifically targeted agentic browsers where the agents can perform actions on websites. Against Perplexity Comet, the researcher found that the browser's built-in agent extension trusted certain Perplexity domains, allowing the attacker to use DNR to remove redirects and inject content scripts capable of communicating directly with the built-in agent. This access facilitated the viewing of browsing history, screenshots, local files, and the ability to instruct the agent to perform tasks, such as summarizing emails and sending results to external addresses. For Microsoft Edge, the vulnerability involved a race condition exploited between the "Think" and "Do" modes, which briefly disabled restrictions while forcing a prompt, allowing the agent to retain action capabilities despite state checks, resulting in CVE-2026-55945. Similar flaws were identified in Claude for Chrome, stemming from earlier weaknesses where the extension trusted the origin of AI workflows without verifying the actual driving script.

Weizman characterized the method used to seize these agents as Prompt Forcing. Unlike conventional prompt injection, which involves inserting malicious instructions into content the AI is already processing, Prompt Forcing involves providing the agent with a complete set of instructions and follow-up commands. The agent then interprets these instructions and translates them into legitimate browser actions by utilizing its existing privileges. This technique poses a significant threat to endpoint defenses because the resulting action is executed by legitimate software rather than conventional malicious code. The discovery highlights that a compromised extension can transform into a pathway for software to read sensitive data, browse data, and act on websites on behalf of the user. Consequently, the research stresses that users should maintain fully updated browsers, remove any unrecognized or unused extensions, and exercise caution regarding broad permission requests, particularly those related to reading and changing data across all websites.