BragJack attacks hijack AI browser agents through malicious extensions
ID: 42148db7-afb8-5def-a525-7dc93652b9af
STIX ID: report--42148db7-afb8-5def-a525-7dc93652b9af
Feed Name: Bleeping Computer
Security researcher Gal Weizman disclosed “BragJack,” a proof-of-concept technique in which a malicious browser extension abuses Chromium’s declarativeNetRequest and other weaknesses to hijack built-in AI assistants in multiple Chromium-based browsers (Google Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic Claude). The attacks—termed “Prompt Forcing”—allow an installed extension to inject prompts or code that cause privileged browser components to access local files, take screenshots, control agents to act on websites, and potentially use camera/microphone; vendors issued fixes and bounties and CVEs were assigned.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
