BragJack: Browser Extension Attack Hijacks AI Assistants
Score: 7/10

BragJack: Browser Extension Attack Hijacks AI Assistants

Researchers at Forever Security demonstrated 'BragJack', a technique using malicious browser extensions to hijack AI assistants in Chrome, Edge, Comet, Opera Neon, and Claude by manipulating trusted domains and network traffic.

Executive Summary

Security researchers at Forever Security have detailed a new attack class called 'BragJack' that targets the integration of AI agents within modern web browsers. By exploiting the architectural split between the browser-resident AI 'body' (which has high-privilege access to local files, cameras, and microphones) and the cloud-based AI 'brain', researchers demonstrated that a low-privilege browser extension can seize control of the assistant. This bypasses traditional security boundaries by manipulating the trusted web pages the AI agents listen to for instructions.

The attack chain involves using standard extension permissions, specifically 'declarativeNetRequest' and content scripts, to inject malicious code or redirect network traffic from trusted vendor domains (e.g., google.com, opera.com, or internal testing domains) to attacker-controlled scripts. This allows for a novel technique called 'Prompt-Forcing', where an attacker sends unauthorized, invisible prompts to the AI agent. The most severe impacts were seen in the Perplexity Comet browser, where the hijacked agent could read local OS files, and Google Chrome, where it could access the camera and microphone.

While these findings are researcher-led demonstrations and not currently seen in the wild, the implications are significant. The vulnerabilities (CVE-2026-0628 and CVE-2026-55945) suggest that the addition of agentic AI features reintroduces high-risk attack surfaces that browsers have historically worked to eliminate. Organizations should ensure browser software is updated to the latest versions and audit installed extensions, as this attack relies on a compromised or malicious extension already being present in the user's environment.

Key Details

Threat Name

CVE-2026-0628 (GlicJack)

Affects

Google Chrome version 143.0.7499.192, Microsoft Edge version 150.0.4078.48, Google Chrome, Microsoft Edge

Adversary

—

Malware/Tools

ClaudeBleed, BragJack

Report Score

7out of 10
Quality Score
Good
IOC Quality2
TTP Details9
Detection Guidance4
Enterprise Relevance8
Clarity & Structure9
Technical Depth8

Sources