A single browser extension, using permissions no more unusual than an ad blocker’s, was enough to seize control of the built-in AI assistants running inside Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome.
The research, published on September 16, 2026, by Gal Weizman of Forever Security, is called BragJack, and it earned more than $20,000 in combined bug bounties from Google, Microsoft, Anthropic, Opera, and Perplexity, along with two formal CVEs.
The attack shows how a compromised browser extension can become a security risk across multiple AI-enabled browsers. Users should install extensions only from trusted sources and review the permissions requested by each extension.
BragJack Attack Hijacks 5 Browsers
What makes BragJack notable isn’t that it bypassed AI guardrails or used prompt injection. Weizman explicitly avoided both.
Every agentic browser he tested is built the same way: a “brain” (the vendor’s cloud-hosted AI, like gemini.google.com or perplexity.ai) issues instructions to a “body” (the privileged browser component that can screenshot tabs, read local files, or activate the camera). Communication between brain and body is supposed to be locked to one trusted web origin.
Weizman found that browser extensions could impersonate that trusted origin through ordinary content-script injection and the declarativeNetRequest (DNR) API used to modify network traffic, feeding the AI agent commands of their own.
He calls this technique “prompt forcing,” distinct from prompt injection because the attacker doesn’t smuggle malicious text into an existing prompt; they write and control the entire instruction stream, including follow-up commands, with zero clicks from the victim.

The flaw first surfaced in Chrome’s Gemini Live panel, tracked as CVE-2026-0628 (CVSS 8.8), which Google patched in Chrome 143.0.7499.192 after Chrome failed to exclude the Gemini WebView from extension DNR rules, letting a basic extension hijack camera, microphone, local files, and screenshot access.
In Opera Neon, the trusted domain opera.com didn’t block extension code injection at all, making it the easiest target; a single crafted prompt could get the agent to summarize and invisibly exfiltrate a victim’s emails.
Microsoft Edge fought back harder, splitting its Copilot agent into “Think” and “Do” modes so it could never receive instructions and act on them at the same time.
Weizman defeated this with a race condition switching modes mid-execution, which Microsoft classified as CVE-2026-55945 and patched in Edge 150.0.4078.48.
Claude in Chrome fell because Anthropic’s own marketing page could pass unrestricted prompts to the extension’s side panel, rated medium severity [web:5].
The worst case was Perplexity Comet, which Weizman called “the most devastating” because Comet’s agent inherits the browser’s full permission set, including OS-level file access.
Perplexity had blocked extensions from perplexity.ai entirely, but a forgotten testing subdomain reachable only after stripping a redirect via DNR gave Weizman a path to full agent hijack, browsing history, screenshots, and local file reads.

Because BragJack involves no malicious payload just a trusted piece of software doing something it’s technically authorized to do traditional EDR tools have nothing to flag.
The attack also scales without custom development: once an agent is hijacked, it can improvise its own exfiltration path rather than requiring a bespoke script per target application.
Google and Microsoft have shipped fixes, but patch status for Comet, Opera Neon, and Claude in Chrome’s underlying architectural weakness remained unconfirmed at the time of disclosure, based on available reporting.
For an industry rapidly wiring agentic AI into everyday software, BragJack warns that the extension-to-agent trust boundary needs the same scrutiny long applied to sandboxing and origin isolation before attackers, not researchers, find the next testing subdomain someone forgot to lock down.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.