DEV Community

Cover image for BragJack: one extension can hijack browser AI agents
techaiwire
techaiwire

Posted on Originally published at techaiwire.com

BragJack: one extension can hijack browser AI agents

A single malicious browser extension can take control of the AI assistants now built into web browsers, security researcher Gal Weizman of Forever Security has shown. He calls the attack BragJack. It worked against five products: Gemini in Google Chrome, Microsoft Edge's assistant, Perplexity Comet, Opera Neon and Anthropic's Claude in Chrome. The attack needs no clicks from the victim once the extension is installed.

This matters because browser AI agents hold far more power than a normal web page. They can see the screen, read files and act on the user's behalf. BragJack hands that power to an extension that was never meant to have it.

How the attack works

The Hacker News explains that a browser AI assistant is split in two. A local part runs in the browser, with access to the screen, files, camera and microphone. A remote part runs on the vendor's servers and does the thinking. The two talk over a channel each side trusts.

BragJack attacks that channel. It uses two extension permissions: one that changes page content and one called declarativeNetRequest. That second permission lets an extension rewrite network requests with rules the browser applies for it. It is the API that replaced the older webRequest system in Manifest V3. That extension format became mandatory when Google removed every Manifest V2 extension from its store earlier this month.

According to BleepingComputer, the extension uses these rules to change security headers and redirect JavaScript files into the browser's privileged AI components. Weizman told BleepingComputer that "browser extensions can manipulate web traffic and pages that these privileged components trust."

Weizman calls the technique "Prompt Forcing." Older attacks hid instructions inside a web page and hoped the AI would obey them. Prompt Forcing instead pushes a complete prompt into the agent through a channel the agent already trusts.

What an attacker could do

BleepingComputer lists what the researcher achieved. A malicious extension could read local files, take screenshots and turn on the camera and microphone. It could also browse the victim's history, intercept communications and steer the AI agent to act for the victim.

The Hacker News adds details per product. On Chrome, the flaw let an extension read local files, use the camera and microphone, take screenshots and leak profile data. On Edge, it used a race condition, a timing gap between the assistant's "think" and "act" steps, to take over the agent.

Which browsers are fixed

Product Identifier Severity Status
Chrome (Gemini) CVE-2026-0628 CVSS 8.8 Fixed in 143.0.7499.192, January 2026
Microsoft Edge CVE-2026-55945 CVSS 4.2 Fixed in 150.0.4078.48, July 2, 2026
Perplexity Comet None assigned Not given No fix confirmed
Opera Neon None assigned Not given No fix confirmed
Claude in Chrome None assigned Not given No fix confirmed

CVSS is the standard 0-to-10 scale security teams use to rank a bug's danger. The Hacker News says the Chrome flaw was first described publicly in March 2026 under the name "GlicJack."

All five vendors paid bug bounties, over $20,000 in total, with single payments from $600 to $7,000. The two reports disagree on how the money was split. BleepingComputer lists Perplexity's payment as $600. The Hacker News lists Perplexity at $7,000 and Anthropic at $600.

What this means for developers

Update Chrome and Edge first. Chrome needs version 143.0.7499.192 or later and Edge needs 150.0.4078.48 or later. Both fixes shipped months ago, so a current browser is already safe from those two CVEs.

For Comet, Opera Neon and Claude in Chrome, neither report confirms a fix. If your team uses them, keep them updated and watch each vendor's release notes.

Audit installed extensions, especially on machines where an AI agent has file or camera access. BragJack starts from an extension the user chose to install. An extension that asks for both page-modification and declarativeNetRequest permissions now deserves a closer look than it did last year.

If you build an AI browser agent, treat the channel between its local and remote halves as hostile ground. Extensions can rewrite requests and headers on that path. Authenticating those messages, instead of trusting whatever arrives, narrows what an injected prompt can do.


This article was first published on Tech AI Wire.

Also available in

Deutsch · 日本語 · Français · Español · Português

Related on Tech AI Wire

Sources

Top comments (0)