BragJack attack lets malicious extensions hijack AI browser agents

Researcher earns over $20,000 in bounties from five vendors for exploiting trusted browser components

By LineZotpaper
Published
Read Time3 min
Security researcher Gal Weizman has disclosed a new attack technique called BragJack that uses a single malicious browser extension to hijack AI assistants built into popular Chromium-based browsers, including Google Chrome's Gemini Live, Microsoft Edge, and Opera Neon. The proof-of-concept, which can run without user interaction, earned more than $20,000 in bug bounties from five vendors, and two CVEs were assigned, with Google and Microsoft already resolving the flaws.

A newly disclosed attack technique, dubbed BragJack, can hijack AI browser assistants using a single malicious browser extension, according to security researcher Gal Weizman of Forever Security. The proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome. Weizman earned more than $20,000 in bug bounties from the vendors, ranging from $600 to $7,000, and the research produced two CVEs.

The attack requires the malicious extension to already be installed in the victim's browser. Once installed, the abuse can run without user interaction, allowing the extension to control an AI browser agent and exploit its existing privileges to access sensitive information or act on the victim's behalf. Both Google and Microsoft have since resolved the flaws they were assigned.

Weizman's writeup describes AI assistants as having a "brain" and a "body": the AI model processes instructions and decides what should happen, while a privileged browser component performs actions such as accessing tabs, reading content, taking screenshots, or interacting with websites. The issue arises because browser extensions can manipulate web traffic and pages that these privileged components trust.

The same extension was used across all five targets, relying on Chromium's declarativeNetRequest (DNR) functionality, which lets extensions modify network requests, including changing response headers and redirecting resources. In the Chrome attack, Weizman found that although extensions were blocked from directly touching the privileged chrome://glic component or injecting scripts into Google's Gemini site, DNR rules could intercept requests made by the embedded Gemini web app. This allowed him to execute code inside the Gemini context and communicate directly with Chrome's privileged AI component, gaining access to local files, web content, screenshots, and potentially the browser's camera and microphone. Chrome assigned CVE-2026-0628 and paid a $7,000 bounty.

Attacks against agentic browsers such as Perplexity Comet and Opera Neon go further because their agents can act on websites rather than merely read them. For Comet, Weizman exploited a testing domain that lacked the protections of the primary site, using DNR to remove a redirect and inject a content script that could talk to the built-in agent. This granted access to browsing history, screenshots, local files, and the ability to send instructions to the agent, including forcing it to summarize the victim's emails and send the results elsewhere.

§

Analysis

Why it matters

  • This attack highlights a critical security gap in the growing integration of AI assistants into browsers, where trusted browser components can be manipulated by malicious extensions.
  • The technique can run without user interaction, meaning a victim who installs a malicious extension could have their sensitive data, including emails and browsing history, silently exfiltrated or their agents used for malicious actions.
  • As AI agents gain more capabilities to act on users' behalf, attacks like BragJack underline the need for stricter isolation and security controls around browser-privileged components.

Background

AI assistants are increasingly built into web browsers, gaining privileged access to tabs, content, and even device hardware like cameras and microphones. This is part of a broader trend of 'agentic' browsers, where AI agents can autonomously interact with websites. Security researchers have repeatedly shown that such features expand the attack surface, particularly when browser extensions—which often have broad permissions—can interact with these assistants.

Key perspectives

  • Researcher (Gal Weizman): Argues that the problem lies in how extensions can manipulate web traffic and pages that privileged browser components trust, enabling full control of the AI assistant without user consent.
  • Browser Vendors (Google, Microsoft): Have patched the identified flaws, with Google assigning CVE-2026-0628 and paying a $7,000 bounty. Their response suggests they take the vulnerability seriously, though the fact that multiple vendors were affected indicates a systemic issue.
  • Critics: May note that the attack requires a malicious extension to already be installed, which is a significant condition. However, malicious extensions are a common attack vector, and the impact of silencing the AI agent without detection makes this a real threat.

What to watch

  • Monitor whether future browser updates introduce additional security measures to restrict extension access to AI assistant components.
  • Watch for the disclosure of the second CVE, which could highlight the scope of the issue across additional browsers.
  • Observe if other agentic browsers adopt stricter domain whitelisting and DNR rule validation to prevent similar hijacking techniques.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.