www.darkreading.com 16 Sept 2026, 16:43 UTC

Browser Extensions Hijacked Chrome and Edge AI Assistants in BragJack Attacks

Browser Extensions Hijacked Chrome and Edge AI Assistants in BragJack Attacks
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Available

SECURITY researcher Gal Weizman of Forever Security has disclosed BragJack, a proof-of-concept attack that hijacked built-in AI assistants in five browser environments: Google Chrome with Gemini, Microsoft Edge, Opera Neon, Perplexity Comet and Claude in Chrome. The research found that browser extensions could cross a security boundary intended to separate untrusted extensions from highly privileged AI agents, allowing attackers to control the assistants without bypassing guardrails or relying on prompt injection.

Forever Security said the affected companies acknowledged vulnerabilities and paid more than $20,000 in bug bounties; Google and Microsoft assigned CVE-2026-0628 and CVE-2026-55945 respectively. The article says the issues have since been resolved.

The specific exploitation method varied. In Chrome, researchers modified network requests used to load Gemini and substituted JavaScript, reportedly enabling screenshots, access to local files, and activation of the camera and microphone without user clicks. In Edge, they chained weaknesses involving a privileged Microsoft marketing page and a race condition between “Think” and “Do” modes to make the agent accept and execute attacker-controlled instructions.

Weizman said the agents could potentially access email, leak information, or perform destructive actions on authenticated websites. He recommends updating Chromium-based browsers, removing unvetted extensions, and reviewing AI-provider interaction records and transcripts for suspicious behaviour. The article says the attacks may bypass existing EDR systems.

View full article

Article by CyberSIXT