A newly disclosed attack technique, dubbed BragJack, can hijack AI browser assistants using a single malicious browser extension, according to security researcher Gal Weizman of Forever Security. The proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome. Weizman earned more than $20,000 in bug bounties from the vendors, ranging from $600 to $7,000, and the research produced two CVEs.
The attack requires the malicious extension to already be installed in the victim's browser. Once installed, the abuse can run without user interaction, allowing the extension to control an AI browser agent and exploit its existing privileges to access sensitive information or act on the victim's behalf. Both Google and Microsoft have since resolved the flaws they were assigned.
Weizman's writeup describes AI assistants as having a "brain" and a "body": the AI model processes instructions and decides what should happen, while a privileged browser component performs actions such as accessing tabs, reading content, taking screenshots, or interacting with websites. The issue arises because browser extensions can manipulate web traffic and pages that these privileged components trust.
The same extension was used across all five targets, relying on Chromium's declarativeNetRequest (DNR) functionality, which lets extensions modify network requests, including changing response headers and redirecting resources. In the Chrome attack, Weizman found that although extensions were blocked from directly touching the privileged chrome://glic component or injecting scripts into Google's Gemini site, DNR rules could intercept requests made by the embedded Gemini web app. This allowed him to execute code inside the Gemini context and communicate directly with Chrome's privileged AI component, gaining access to local files, web content, screenshots, and potentially the browser's camera and microphone. Chrome assigned CVE-2026-0628 and paid a $7,000 bounty.
Attacks against agentic browsers such as Perplexity Comet and Opera Neon go further because their agents can act on websites rather than merely read them. For Comet, Weizman exploited a testing domain that lacked the protections of the primary site, using DNR to remove a redirect and inject a content script that could talk to the built-in agent. This granted access to browsing history, screenshots, local files, and the ability to send instructions to the agent, including forcing it to summarize the victim's emails and send the results elsewhere.