BragJack Attacks Hijack AI Browser Agents: One Malicious Extension Can Control Chrome, Edge, Comet and More

BragJack Attacks Hijack AI Browser Agents: One Malicious Extension Can Control Chrome, Edge, Comet and More

BragJack Attacks Hijack AI Browser Agents: One Malicious Extension Can Control Chrome, Edge, Comet and More

Security researcher Gal Weizman of Forever Security has disclosed a new attack technique that hijacks the AI assistants built into popular browsers using a single malicious extension. Dubbed BragJack, the proof-of-concept was demonstrated against five Chromium-based targets: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome. The work earned more than $20,000 in bug bounties across the five vendors and produced two CVEs, and both Google and Microsoft have resolved the flaws assigned to them.

The attack requires a malicious extension to already be installed in the victim's browser. Once it is, the abuse runs without further user interaction: the extension controls the AI browser agent and abuses the privileges the agent already holds — reading tabs, taking screenshots, reaching local files, and interacting with websites on the victim's behalf.

Trusted Components, Manipulated Traffic

Weizman describes these AI assistants as having a "brain" and a "body": the model processes instructions and decides what should happen, and a privileged browser component performs the actions — accessing tabs, reading content, taking screenshots, or interacting with websites. The problem is that ordinary extensions can manipulate the web traffic and pages those privileged components trust. All five attacks rely on Chromium's declarativeNetRequest (DNR) functionality, which lets extensions modify how network requests are handled, including response headers and resource redirects.

In Chrome, extensions were blocked from touching the privileged chrome://glic component or injecting scripts into Google's Gemini site. But DNR rules could still intercept requests made by the embedded Gemini web app: Weizman weakened security headers and redirected a JavaScript resource to execute code inside the Gemini context, then talked directly to Chrome's privileged AI component rather than going through Gemini's normal request flow. The resulting access could read local files, reach web content, take screenshots, and potentially reach the camera and microphone. Chrome assigned the finding CVE-2026-0628 and paid a $7,000 bounty.

Against agentic browsers the attack goes further, because their agents act on websites rather than merely reading them. In Perplexity Comet, the built-in agent extension trusted several Perplexity domains — including a testing domain that did not get the same protections as the primary site. Weizman removed a redirect with DNR, loaded that domain, and injected a content script able to talk to the built-in agent — with access to browsing history, screenshots, and local files, and the ability to send the agent instructions. He demonstrated forcing the agent to visit Perplexity, summarize the victim's emails, and send the results to another address.

Microsoft had split its Edge agent into "Think" and "Do" modes to stop it from taking arbitrary instructions and actions at the same time. Weizman found a race condition — CVE-2026-55945 — that briefly disables the restriction while forcing a prompt, then re-enables the action capability before the agent checks its state. Similar flaws were demonstrated against Opera Neon and Claude in Chrome, though the latter is itself a browser extension rather than a browser.

Prompt Forcing

Weizman calls the technique used to seize these agents "Prompt Forcing." Unlike conventional prompt injection, where an attacker tries to slip malicious instructions into content an AI is already reading, Prompt Forcing hands the agent an entire prompt and the follow-up instructions. The agent then translates those instructions into legitimate browser actions using its existing privileges. That matters for endpoint defenses: the final action is not carried out by conventional malicious code — legitimate software is being told to perform the attack.

The findings extend a growing pattern. In April, LayerX disclosed ClaudeBleed, a flaw in which Claude for Chrome trusted the claude.ai origin rather than checking which script was actually driving it, and a related weakness — Claude for Chrome running its built-in AI workflows on synthetic clicks without verifying they came from a real user — was flagged and still reproducible eight releases later.

What Should You Do?

  1. Keep browsers fully updated — Google and Microsoft have already shipped fixes for their assigned CVEs.
  2. Audit installed extensions and remove anything you do not recognize or no longer use; one extension is the entire prerequisite for BragJack.
  3. Treat "read and change all your data on all websites" permission prompts as high-risk — that permission is exactly what these attacks monetize.
  4. Inventory which AI agents hold privileges in your browsers and scope what they can reach. An agent that can read files and act on sites is a privileged identity, not a feature.

The WAF Angle

BragJack is a web-content problem wearing an endpoint costume. The malicious instructions reach the agent through manipulated responses and injected scripts — traffic that content-security controls were built to police. If your users run browser agents against your web properties, poisoned page content no longer just phishes humans; it can command software that acts with the browser's full authority. Content-Security-Policy enforcement, script-source restrictions, and response-integrity checks all become agent-defense controls in this model. The deeper lesson for defenders tracking agent abuse: the perimeter is no longer the page — it is everything the agent can touch. Inventory your agents the way you inventory accounts, scope their reach, and monitor what they do.

Sources