BragJack attacks hijack AI browser agents through malicious extensions
Security researcher Gal Weizman reveals a new attack technique that can hijack AI assistants built into popular browsers using a single malicious browser extension.
Intelligence analysis by Qwen 2.5 (3B)

Security researcher Gal Weizman discovers a new attack method that leverages a malicious browser extension to hijack AI assistants in popular browsers like Google Chrome, Microsoft Edge, and Anthropic's Claude.
Imagine a bad guy puts a sneaky extension in your browser. This extension can trick a smart helper in your browser into doing bad things, like looking at your private stuff or sending your secrets to someone else.
Analysis
{"heading_1":"The Attack Mechanism","paragraph_1":"The attack is achieved by exploiting the way AI assistants are integrated into browsers, which are granted browser-level capabilities. The malicious extension uses Chromium's declarativeNetRequest (DNR) functionality to manipulate network requests and intercept requests made by the embedded AI assistant.","paragraph_2":"In the Chrome attack, the researcher found that extensions were blocked from directly touching the privileged chrome://glic component or injecting scripts into Google's Gemini site. However, DNR rules could still intercept requests made by the embedded Gemini web app, allowing the extension to execute code inside the Gemini context and communicate directly with Chrome's privileged AI component.","paragraph_3":"For Comet, the browser's built-in agent extension trusted several Perplexity domains, including a testing domain that did not get the same protections as the primary perplexity.ai site. By removing a redirect to that domain with DNR, the researcher loaded it and injected a content script able to talk to the built-in agent, allowing access to browsing history, screenshots, local files, and the ability to send instructions to the agent.","paragraph_4":"Microsoft Edge presented a different challenge, as it had split its agent into 'Think' and 'Do' modes to prevent arbitrary instructions and actions. The researcher found a race condition that briefly disables the restriction while forcing a prompt, then re-enables the action capability before the agent checks its state.","paragraph_5":"Claude in Chrome is itself a browser extension rather than a browser. The extension ran its built-in AI workflows on synthetic clicks without verifying they came from a real user, leading to a flaw that was disclosed earlier this year.","paragraph_6":"The researcher calls the technique used to seize these agents 'Prompt Forcing', where an attacker hands the agent an entire prompt and follow-up instructions, allowing the agent to translate those instructions into legitimate browser actions using its existing privileges.","paragraph_7":"This attack points to a growing challenge as browsers and other endpoint apps gain more capable AI agents, potentially leading to data breaches and unauthorized actions. Users should keep browsers fully updated, remove unrecognized or unused extensions, and be cautious of broad 'read and change all your data on all websites' permission prompts.","paragraph_8":"Weizman has published a full technical breakdown covering all five attacks, providing a comprehensive understanding of the vulnerabilities and potential impacts of such attacks."}
Key points
- BragJack attack uses a single malicious browser extension to hijack AI assistants in popular browsers.
- The attack exploits the way AI assistants are integrated into browsers, which are granted browser-level capabilities.
- The malicious extension uses Chromium's declarativeNetRequest (DNR) functionality to manipulate network requests and intercept requests made by the embedded AI assistant.
- The attack can read local files, take screenshots, and potentially reach the browser's camera and microphone.
- Users should keep browsers fully updated, remove unrecognized or unused extensions, and be cautious of broad 'read and change all your data on all websites' permission prompts.
As browsers and AI assistants get better, they will likely have more built-in security to prevent such attacks. Users should keep their browsers updated and be careful about which extensions they use.
If the bad guy gets past the browser's security, they could use the sneaky extension to trick the AI helper into doing harmful things. This could lead to data breaches and other security issues.



