Skip to main content
Get facts, not fiction
Published • loading... • Updated

BragJack Attacks Hijack AI Browser Agents Through Malicious Extensions

Summary by BleepingComputer
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs.

6 Articles

BragJack is a method of using AI assistants in browsers to read data and execute dangerous and unsolicited commands. There are two good news, however: the method was developed by researchers, so it's not the repertoire of hackers alone. Furthermore, such an attack requires a previously installed malicious extension, but it can be achieved. I even fell victim to this myself once: however, the extension "went rogue" after an update, and only 2FA p…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Cyber Security News broke the news on Saturday, September 19, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal