Executive Summary
Security researchers at Forever Security have detailed a new attack class called 'BragJack' that targets the integration of AI agents within modern web browsers. By exploiting the architectural split between the browser-resident AI 'body' (which has high-privilege access to local files, cameras, and microphones) and the cloud-based AI 'brain', researchers demonstrated that a low-privilege browser extension can seize control of the assistant. This bypasses traditional security boundaries by manipulating the trusted web pages the AI agents listen to for instructions.
The attack chain involves using standard extension permissions, specifically 'declarativeNetRequest' and content scripts, to inject malicious code or redirect network traffic from trusted vendor domains (e.g., google.com, opera.com, or internal testing domains) to attacker-controlled scripts. This allows for a novel technique called 'Prompt-Forcing', where an attacker sends unauthorized, invisible prompts to the AI agent. The most severe impacts were seen in the Perplexity Comet browser, where the hijacked agent could read local OS files, and Google Chrome, where it could access the camera and microphone.
While these findings are researcher-led demonstrations and not currently seen in the wild, the implications are significant. The vulnerabilities (CVE-2026-0628 and CVE-2026-55945) suggest that the addition of agentic AI features reintroduces high-risk attack surfaces that browsers have historically worked to eliminate. Organizations should ensure browser software is updated to the latest versions and audit installed extensions, as this attack relies on a compromised or malicious extension already being present in the user's environment.
