logo

BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers

ID: 10c6a245-5e9b-544c-8628-9ed787d9d84c

STIX ID: report--10c6a245-5e9b-544c-8628-9ed787d9d84c

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

Author: Guru Baran

...
...

The report details “BragJack,” a prompt-forcing technique where malicious browser extensions exploit content scripts and declarativeNetRequest rules to inject commands into privileged AI assistant control planes across Chromium-based browsers (Chrome/Gemini, Edge/Copilot, Opera Neon, Comet, and Claude in Chrome). Researchers demonstrated the ability to read local files, capture screenshots, leak profiles, and activate cameras/microphones by manipulating trusted origins or resources; Google and Microsoft assigned CVEs and issued fixes. Recommendations include updating browsers, removing unnecessary extensions, enforcing extension allowlists, restricting broad host/DNR permissions, and treating AI-agent activity as distinct telemetry for detection and audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.