<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions-tgnh2pcif" -->

---
title: BragJack attacks hijack AI browser agents through...
description: Security researcher Gal Weizman of Forever Security disclosed BragJack, a proof-of-concept attack technique that hijacks AI browser assistants across five...
canonical: https://daily.dev/posts/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions-tgnh2pcif
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: BragJack attacks hijack AI browser agents through malicious extensions | daily.dev
og:description: Security researcher Gal Weizman of Forever Security disclosed BragJack, a proof-of-concept attack technique that hijacks AI browser assistants across five...
og:url: https://daily.dev/posts/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions-tgnh2pcif
og:image: https://api.daily.dev/og/posts/TgnH2PCIF.png
og:image:alt: BragJack attacks hijack AI browser agents through malicious extensions
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# BragJack attacks hijack AI browser agents through malicious extensions

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 5 min read · 0 upvotes · 0 comments

## Summary

Security researcher Gal Weizman of Forever Security disclosed BragJack, a proof-of-concept attack technique that hijacks AI browser assistants across five Chromium-based browsers—Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome—using a single malicious extension already installed on the victim's machine. The extension abuses Chromium's declarativeNetRequest API to intercept and redirect network traffic, letting an attacker execute code in the privileged AI assistant context and take over the agent using a technique called Prompt Forcing, where the attacker hands the agent a full prompt and instructions rather than injecting content. Demonstrated impacts included reading local files, browsing history, screenshots, and forcing agents to exfiltrate email summaries. The research earned over $20,000 in bug bounties and produced two CVEs (CVE-2026-0628 for Chrome, CVE-2026-55945 for a race condition in Edge); Google and Microsoft have patched their flaws. Users are advised to remove unrecognized extensions and scrutinize broad site-access permissions.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions>

## Questions this post answers

### What is the BragJack attack and how does it hijack AI browser agents?

BragJack is a proof-of-concept attack by researcher Gal Weizman that uses a single malicious browser extension already installed in a victim's browser to hijack AI assistants in Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome. It abuses Chromium's declarativeNetRequest API to intercept network requests, execute code in the privileged AI context, and control the agent using a technique called Prompt Forcing, without requiring user interaction.

_Track emerging AI agent security research like this by following security news on daily.dev._

### What CVEs came out of the BragJack browser AI agent research?

The research produced two CVEs: CVE-2026-0628, assigned to Chrome for a flaw letting a malicious extension read local files, screenshots, and browser content through the Gemini Live component, which earned a $7,000 bounty; and CVE-2026-55945, assigned to Microsoft Edge for a race condition that briefly disabled the 'Think/Do' safeguard separating instruction processing from action execution. Both Google and Microsoft have since patched their respective issues.

_Developers patching browser extensions or agent integrations can follow CVE disclosures like these via daily.dev._

### How is Prompt Forcing different from regular prompt injection attacks?

Prompt Forcing differs from conventional prompt injection because instead of sneaking malicious instructions into content an AI is already reading, the attacker hands the AI agent an entire prompt plus follow-up instructions directly. The agent then carries out those instructions as legitimate browser actions using its existing privileges, meaning the final malicious action is performed by trusted software rather than detectable malicious code, complicating endpoint defenses.

_Anyone building or evaluating AI agent security models can dig deeper into threats like this via daily.dev._

## Similar posts on daily.dev

- [Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel](https://daily.dev/posts/taming-agentic-browsers-vulnerability-in-chrome-allowed-extensions-to-hijack-new-gemini-panel-wrgfp6s8g) · Unit 42 · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#devtools](https://daily.dev/tags/devtools), [#ai-agents](https://daily.dev/tags/ai-agents), [#google-chrome](https://daily.dev/tags/google-chrome), [#prompt-injection](https://daily.dev/tags/prompt-injection)

[View this post on daily.dev](https://daily.dev/posts/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions-tgnh2pcif)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"BragJack attacks hijack AI browser agents through malicious extensions","url":"https://daily.dev/posts/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions-tgnh2pcif","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions-tgnh2pcif"},"datePublished":"2026-09-19T14:57:21.692Z","dateModified":"2026-09-19T15:41:10.473Z","description":"Security researcher Gal Weizman of Forever Security disclosed BragJack, a proof-of-concept attack technique that hijacks AI browser assistants across five...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1c4914829c49315063e7ef552843f397?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1c4914829c49315063e7ef552843f397?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions-tgnh2pcif","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,devtools,ai-agents,google-chrome,prompt-injection","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"BragJack attacks hijack AI browser agents through malicious extensions"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions-tgnh2pcif#faq","mainEntity":[{"@type":"Question","name":"What is the BragJack attack and how does it hijack AI browser agents?","acceptedAnswer":{"@type":"Answer","text":"BragJack is a proof-of-concept attack by researcher Gal Weizman that uses a single malicious browser extension already installed in a victim's browser to hijack AI assistants in Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome. It abuses Chromium's declarativeNetRequest API to intercept network requests, execute code in the privileged AI context, and control the agent using a technique called Prompt Forcing, without requiring user interaction. Track emerging AI agent security research like this by following security news on daily.dev."}},{"@type":"Question","name":"What CVEs came out of the BragJack browser AI agent research?","acceptedAnswer":{"@type":"Answer","text":"The research produced two CVEs: CVE-2026-0628, assigned to Chrome for a flaw letting a malicious extension read local files, screenshots, and browser content through the Gemini Live component, which earned a $7,000 bounty; and CVE-2026-55945, assigned to Microsoft Edge for a race condition that briefly disabled the 'Think/Do' safeguard separating instruction processing from action execution. Both Google and Microsoft have since patched their respective issues. Developers patching browser extensions or agent integrations can follow CVE disclosures like these via daily.dev."}},{"@type":"Question","name":"How is Prompt Forcing different from regular prompt injection attacks?","acceptedAnswer":{"@type":"Answer","text":"Prompt Forcing differs from conventional prompt injection because instead of sneaking malicious instructions into content an AI is already reading, the attacker hands the AI agent an entire prompt plus follow-up instructions directly. The agent then carries out those instructions as legitimate browser actions using its existing privileges, meaning the final malicious action is performed by trusted software rather than detectable malicious code, complicating endpoint defenses. Anyone building or evaluating AI agent security models can dig deeper into threats like this via daily.dev."}}]}
```

