BragJack Attack Can Hijack AI Assistants in Chrome, Edge, and Other Browsers
BragJack, a newly disclosed proof-of-concept attack, can let malicious browser extensions hijack AI assistants built into Chromium-based browsers.
Security researcher Gal Weizman of Forever Security demonstrated the attack against Google Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome.
The malicious extension must already be installed in the victim’s browser. After installation, however, the demonstrated attacks can run without further user interaction.
BragJack uses Prompt Forcing to control AI agents
Weizman calls the broader technique Prompt Forcing. Instead of hiding malicious instructions inside content, an attacker can supply an AI assistant with a complete prompt and follow-up instructions.
The AI then executes those instructions through legitimate browser features and its existing privileges.
BragJack abuses the separation between the AI model and privileged browser components that can read tabs, access page content, capture screenshots, and interact with websites.
The same extension worked across all five tested browsers by abusing Chromium’s declarativeNetRequest functionality to manipulate requests, headers, and resources.
In Chrome, the attack could manipulate requests from the embedded Gemini application, weaken security headers, and redirect JavaScript resources. The researcher demonstrated access to local files, web content, screenshots, and potentially the camera and microphone.
Agentic browsers can create even greater risks. In Perplexity Comet, Weizman demonstrated forcing the assistant to access a victim’s emails, summarize them, and send the information to another address.
Microsoft and Google have fixed reported flaws
Microsoft Edge used separate “Think” and “Do” modes to keep instruction processing and browser actions apart. Weizman found a race condition that could temporarily bypass that separation.
Microsoft assigned the issue CVE-2026-55945 and has since fixed it. Google has also fixed the vulnerability reported in Chrome.
Users should keep browsers updated and remove extensions they no longer recognize or need. Extensions with permission to read and change data across all websites deserve particular scrutiny.
In other news, fake LastPass GitHub repositories are pushing Rapuncel malware, while hackers are mass-scanning Vite servers to steal AWS and Azure credentials.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages