New “BragJack” Attack Technique Discovered That Can Control Browser-Based AI Assistants Through Extensions

Views: 49 views

517/69 Monday, September 21, 2026

Security researchers from Forever Security have disclosed a new attack technique named “BragJack,” which allows threat actors to take control of artificial intelligence assistants installed in popular web browsers by using malicious extensions already present on a victim’s system. The attack primarily affects browsers or tools based on Chromium, including Google Chrome with Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic Claude in Chrome. The key risk of this technique is that it could allow attackers to instruct trusted AI systems to access sensitive information or perform actions on behalf of users, without requiring further interaction or approval from the victim.

The attack abuses the elevated privileges granted to browser-based AI assistants. Attackers use an installed extension to manipulate the declarativeNetRequest (DNR) mechanism in order to intercept and modify network requests associated with the AI system. Researchers refer to this sub-technique as “Prompt Forcing,” which enables attackers to deliver a complete set of instructions to a trusted AI agent and make it carry out the attack. Potential actions include reading local files, accessing browsing history, capturing screenshots, using the camera and microphone, or forcing the AI assistant to summarize private email content and send the information to a third party. The vulnerabilities identified in this research were assigned CVE-2026-0628 for Google systems and CVE-2026-55945 for Microsoft, and both providers have already released patches to address the flaws.

This incident highlights a new security challenge as software increasingly integrates AI capabilities. Browser extensions that previously had limited scope may become a pathway for deeper and more dangerous system control. To reduce risk, users and administrators should review and remove browser extensions that are unused or come from untrusted sources. They should also be especially cautious when granting broad permissions, such as permission to read and change data on all websites. Most importantly, browsers and operating systems should be kept updated to the latest versions to ensure that newly discovered vulnerabilities are patched in a timely manner.

Source: https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/