INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
BragJack Hijacks AI Browser Agents via Malicious Extensions
| 2026-09-19 14:56 HIGH HIGH SUPPLY CHAIN MALWARE & BOTNETS
Executive Summary
AI-generated
A new attack technique, dubbed BragJack, has been disclosed by security researcher Gal Weizman of Forever Security. The proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome on September 19, 2026. This attack exploits the way AI assistants are increasingly wired into browsers and handed browser-level capabilities, allowing a malicious extension to hijack an AI assistant and access sensitive information or act on behalf of the victim without user interaction. The attack works by manipulating web traffic and pages that trusted browser components trust, using Chromium's declarativeNetRequest (DNR) functionality to intercept requests made by embedded web apps and communicate directly with Chrome's privileged AI component. Both Google and Microsoft have since resolved the flaws they were assigned, with Chrome assigning CVE-2026-0628 and paying a $7,000 bounty.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-55945, CVE-2026-0628 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-55945CVE-2026-55945
CVE-2026-0628CVE-2026-0628
Target & Sectors
Global Scope
Incident Timeline
2026/09/16
Threat actors used malicious extensions to hijack AI browser agents, prompting Forever Security researcher Gal Weizman to discover and exploit the vulnerabilities.
Click on any entity below to view its context and source!
organisation
Forever Security
Gal Weizman, an agentic software and browser vulnerability researcher at Forever Security, discovered the attack, which he said garnered the firm more than $20,000 in bug bounties from the companies affected, according to a
blog post
published today.
financial
$20,000 research
Gal Weizman, an agentic software and browser vulnerability researcher at Forever Security, discovered the attack, which he said garnered the firm more than $20,000 in bug bounties from the companies affected, according to a
blog post
published today.
2026/09/19
Threat actors used a malicious browser extension to hijack AI assistants built into popular browsers using Chromium's declarativeNetRequest (DNR) functionality.
Click on any entity below to view its context and source!
financial
$7,000 $ bounty
Chrome assigned the finding
CVE-2026-0628
and paid a $7,000 bounty.
organisation
Forever Security
Security researcher Gal Weizman of Forever Security has disclosed a new attack technique that can hijack the AI assistants built into popular browsers using a single malicious browser extension.
organisation
Chromium
Dubbed BragJack, the proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome.
In the immediate term, Weizman recommends that organizations keep every Chromium-based browser in the organization up to date and "remove any extension that the organization has not vetted and that is not well known and safe to use," he says.
organisation
Google Chrome's
Dubbed BragJack, the proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome.
organisation
Gemini Live
Dubbed BragJack, the proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome.
organisation
Microsoft Edge
Dubbed BragJack, the proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome.
A new type of proof-of-concept attack called BragJack can compromise five agentic browser environments and steal secrets:
Google Chrome
with Gemini,
Microsoft Edge
,
Opera Neon
, Perplexity Comet, and Claude in Chrome.
organisation
Opera Neon
Dubbed BragJack, the proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome.
A new type of proof-of-concept attack called BragJack can compromise five agentic browser environments and steal secrets:
Google Chrome
with Gemini,
Microsoft Edge
,
Opera Neon
, Perplexity Comet, and Claude in Chrome.
organisation
Perplexity Comet
A new type of proof-of-concept attack called BragJack can compromise five agentic browser environments and steal secrets:
Google Chrome
with Gemini,
Microsoft Edge
,
Opera Neon
, Perplexity Comet, and Claude in Chrome.
From reading data to controlling AI agents
The attacks against agentic browsers such as Perplexity Comet and Opera Neon go further, because their agents can act on websites rather than merely read them.
organisation
Google
Both Google and Microsoft have since resolved the flaws they were assigned.
Forever Security contacted the five companies affected by the attack: Google, Microsoft, Opera, Anthropic, and Perplexity.
organisation
Microsoft
Both Google and Microsoft have since resolved the flaws they were assigned.
Forever Security contacted the five companies affected by the attack: Google, Microsoft, Opera, Anthropic, and Perplexity.
organisation
Perplexity
Forever Security contacted the five companies affected by the attack: Google, Microsoft, Opera, Anthropic, and Perplexity.
For Comet, Weizman found the browser's built-in agent extension trusted several Perplexity domains, including a testing domain that did not get the same protections as the primary perplexity.ai site.
organisation
DNR
The same extension was used across all five targets, relying on Chromium's
declarativeNetRequest
(DNR) functionality.
organisation
Gemini
By weakening security headers and redirecting a JavaScript resource, he executed code inside the Gemini context, communicating directly with Chrome's privileged AI component rather than going through Gemini's normal request flow.
Related:
SpiderSilk Hunts External Threats With AI-Based Scanner
In
Google Chrome/Gemini
, for example, Chrome blocked extensions from injecting scripts into Gemini's page but did not prevent an extension from modifying the network requests used to load Gemini.
organisation
SpiderSilk Hunts External
Related:
SpiderSilk Hunts External Threats With AI-Based Scanner
In
Google Chrome/Gemini
, for example, Chrome blocked extensions from injecting scripts into Gemini's page but did not prevent an extension from modifying the network requests used to load Gemini.
organisation
Manifold Security
Earlier this year, in my work at Manifold Security, I
reported
a related weakness in Claude for Chrome: the extension ran its built-in AI workflows on synthetic clicks without verifying they came from a real user, and the flagged code was still reproducible eight releases later.
organisation
ClaudeBleed
That followed
ClaudeBleed
, an earlier flaw in the same extension that LayerX disclosed in April, in which Claude for Chrome trusted the
claude.ai
origin rather than checking which script was actually driving it.
organisation
Users
Users should keep browsers fully updated, remove extensions they do not recognize or no longer use, and treat broad "read and change all your data on all websites" permission prompts with caution.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
financial
$20,000 research
The research earned more than $20,000 in bug bounties from the five vendors, ranging from $600 to $7,000, and produced two CVEs.
infrastructure
Windows
Related:
VectraRAT Can Hack Windows Enterprises for $250 per Month
"They didn't need to cleverly hide instructions in data the agent interacts with, hoping it would take the bait; they could just send one prompt after the other until the agent got convinced to do anything," Weizman says in an email interview.
organisation
Microsoft Edge/Copilot
In another example, to implement BragJack in Microsoft Edge/Copilot, the researchers had to chain together two weaknesses because they faced stronger defenses, according to the post.
organisation
EDR
While the attacks can
bypass current endpoint detection and response (EDR) systems
, there are ways that a security operations center (SOC) can set up detections by observing past interactions with the AI providers of each agentic browser and identifying potentially affected endpoints, Weizman tells Dark Reading.
organisation
SOC
While the attacks can
bypass current endpoint detection and response (EDR) systems
, there are ways that a security operations center (SOC) can set up detections by observing past interactions with the AI providers of each agentic browser and identifying potentially affected endpoints, Weizman tells Dark Reading.
Tactical Metrics
Metrics
financial
7,000
$ Bounty
Click for context!
Chrome assigned the finding
CVE-2026-0628
and paid a $7,000 bounty.
Metrics
financial
20,000
Research
The research earned more than $20,000 in bug bounties from the five vendors, ranging from $600 to $7,000, and produced two CVEs.
Gal Weizman, an agentic software and browser vulnerability researcher at Forever Security, discovered the attack, which he said garnered the firm more than $20,000 in bug bounties from the companies affected, according to a
blog post
published today.
Metrics
infrastructure
Windows
Affected Product
Related:
VectraRAT Can Hack Windows Enterprises for $250 per Month
"They didn't need to cleverly hide instructions in data the agent interacts with, hoping it would take the bait; they could just send one prompt after the other until the agent got convinced to do anything," Weizman says in an email interview.
Intelligence Sources
BleepingComputer
2026-09-19
Dark Reading
2026-09-16
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T12:17
Comprehensive Tactical Telemetry
Highly Correlated Entities
22x
organisation
Identified Entity
Forever Security
entity
2x
vulnerability
Exploited CVE
CVE-2026-0628
cve
2x
industry
Targeted Sector
Technology
sector
Contextual Telemetry
Context Block
5 METRICS
financial
$ Bounty
7,000
$ bounty
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
financial
Research
20,000
research
timeline
Temporal Reference
2026/09/16
date
infrastructure
Affected Product
Windows
software
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.