discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

BragJack attacks hijack AI browser agents through malicious extensions

Security researcher Gal Weizman reveals a new attack technique that can hijack AI assistants built into popular browsers using a single malicious browser extension.

By Ax Sharma·Sep 19·bleepingcomputer.com·3 min read

Intelligence analysis by Qwen 2.5 (3B)

BragJack attacks hijack AI browser agents through malicious extensions
Image: bleepingcomputer.com

Security researcher Gal Weizman discovers a new attack method that leverages a malicious browser extension to hijack AI assistants in popular browsers like Google Chrome, Microsoft Edge, and Anthropic's Claude.

Why it matters

This attack highlights a vulnerability in browser security, where a single malicious extension can compromise AI assistants, potentially leading to data breaches and unauthorized actions.

Imagine a bad guy puts a sneaky extension in your browser. This extension can trick a smart helper in your browser into doing bad things, like looking at your private stuff or sending your secrets to someone else.

Analysis

{"heading_1":"The Attack Mechanism","paragraph_1":"The attack is achieved by exploiting the way AI assistants are integrated into browsers, which are granted browser-level capabilities. The malicious extension uses Chromium's declarativeNetRequest (DNR) functionality to manipulate network requests and intercept requests made by the embedded AI assistant.","paragraph_2":"In the Chrome attack, the researcher found that extensions were blocked from directly touching the privileged chrome://glic component or injecting scripts into Google's Gemini site. However, DNR rules could still intercept requests made by the embedded Gemini web app, allowing the extension to execute code inside the Gemini context and communicate directly with Chrome's privileged AI component.","paragraph_3":"For Comet, the browser's built-in agent extension trusted several Perplexity domains, including a testing domain that did not get the same protections as the primary perplexity.ai site. By removing a redirect to that domain with DNR, the researcher loaded it and injected a content script able to talk to the built-in agent, allowing access to browsing history, screenshots, local files, and the ability to send instructions to the agent.","paragraph_4":"Microsoft Edge presented a different challenge, as it had split its agent into 'Think' and 'Do' modes to prevent arbitrary instructions and actions. The researcher found a race condition that briefly disables the restriction while forcing a prompt, then re-enables the action capability before the agent checks its state.","paragraph_5":"Claude in Chrome is itself a browser extension rather than a browser. The extension ran its built-in AI workflows on synthetic clicks without verifying they came from a real user, leading to a flaw that was disclosed earlier this year.","paragraph_6":"The researcher calls the technique used to seize these agents 'Prompt Forcing', where an attacker hands the agent an entire prompt and follow-up instructions, allowing the agent to translate those instructions into legitimate browser actions using its existing privileges.","paragraph_7":"This attack points to a growing challenge as browsers and other endpoint apps gain more capable AI agents, potentially leading to data breaches and unauthorized actions. Users should keep browsers fully updated, remove unrecognized or unused extensions, and be cautious of broad 'read and change all your data on all websites' permission prompts.","paragraph_8":"Weizman has published a full technical breakdown covering all five attacks, providing a comprehensive understanding of the vulnerabilities and potential impacts of such attacks."}

Key points

  • BragJack attack uses a single malicious browser extension to hijack AI assistants in popular browsers.
  • The attack exploits the way AI assistants are integrated into browsers, which are granted browser-level capabilities.
  • The malicious extension uses Chromium's declarativeNetRequest (DNR) functionality to manipulate network requests and intercept requests made by the embedded AI assistant.
  • The attack can read local files, take screenshots, and potentially reach the browser's camera and microphone.
  • Users should keep browsers fully updated, remove unrecognized or unused extensions, and be cautious of broad 'read and change all your data on all websites' permission prompts.
The Upside

As browsers and AI assistants get better, they will likely have more built-in security to prevent such attacks. Users should keep their browsers updated and be careful about which extensions they use.

The Downside

If the bad guy gets past the browser's security, they could use the sneaky extension to trick the AI helper into doing harmful things. This could lead to data breaches and other security issues.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagsai-agentssecuritybrowsersmalwareencryption

Author

Ax Sharma

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 19, 2026

Source

bleepingcomputer.com

Share

Topics

ai-agentssecuritybrowsersmalwareencryption

Related

More from this desk

Oct 7·thehackernews.com

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.

Oct 7·bleepingcomputer.com

Microsoft Outlook to block MSIX attachments starting November

Microsoft Outlook to block MSIX attachments starting November 2026.

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.