← Back to feed
AI SecurityEmerging1 sourceSep 19, 2026 · 03:05via Cyber Security News

BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers

Brief

A new attack technique dubbed “BragJack” allows a malicious browser extension to seize trusted communication channels used by AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome.

Rather than bypassing model guardrails or hiding instructions inside web content, the proof-of-concept attacks directly supplied commands to privileged browser components, turning an assistant into a tool for theft and unauthorized actions.

Forever Security researcher Gal Weizman demonstrated the technique across all five Chromium-based environments using one extension with browser-specific rules.

The extension primarily used content scripts and the declarativeNetRequest API (DNR), which can modify network traffic. Commonly used by ad blockers, these capabilities helped untrusted code cross into a privileged AI control plane.

Read more on Cyber Security News→