BragJack Attacks Hijack AI Browser Agents Through Malicious Extensions
6 Articles
6 Articles
BragJack attacks hijack AI browser agents through malicious extensions
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs.
BragJack is a method of using AI assistants in browsers to read data and execute dangerous and unsolicited commands. There are two good news, however: the method was developed by researchers, so it's not the repertoire of hackers alone. Furthermore, such an attack requires a previously installed malicious extension, but it can be achieved. I even fell victim to this myself once: however, the extension "went rogue" after an update, and only 2FA p…
BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers
A new attack technique dubbed “BragJack” allows a malicious browser extension to seize trusted communication channels used by AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. Rather than bypassing model guardrails or hiding instructions inside web content, the proof-of-concept attacks directly supplied commands to privileged browser components, turning an assistant into […]
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium




![[Opinion] AI Companies Prepare For Public Backlash After Potential Catastrophic Incident: Report](/_next/image?url=https%3A%2F%2Fgrnd.b-cdn.net%2Finterest%2Fecdb1a69d41d458d91b104d1334702221ef2554f.jpg&w=1440&q=75)



