BragJack attack hijacks AI browser agents via malicious extensions

Security researcher Gal Weizman of Forever Security disclosed BragJack, a proof-of-concept attack exploiting malicious browser extensions to seize control of AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. Bounties of $20,000 were awarded to demonstrate that automation amplifies social-engineering vulnerabilities.

9 reports · 8 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Malicious extension hijacks AI browser agents across five browsers

kite:cybersecurityother11d ago kagi ↗

Security researcher Gal Weizman disclosed BragJack, a proof-of-concept technique that uses a malicious browser extension to seize control of AI assistants integrated into five Chromium-based environments: Google Chrome’s Gemini Live, Microsoft Edge, Perplexity Comet, Opera Neon and Anthropic’s Claude in Chrome [cybersecuritynews.com#1][bleepingcomputer.com#1]. The attack does not require bypassing

BragJack attacks hijack AI browser agents through malicious extensions

rss:bleepingcomputertech10d ago wire ×2 kagi ↗

BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. [...]

🤖 BragJack: one malicious extension hijacks AI browser assistants in Chrome, Edge, Opera Neon, Perplexity Comet and Claude. Prompt Forcing technique earned $20,000 in bounties and two CVEs. 🔗 https:

mastodon:infosec-exchangeother10d ago kagi ↗

🤖 BragJack: one malicious extension hijacks AI browser assistants in Chrome, Edge, Opera Neon, Perplexity Comet and Claude. Prompt Forcing technique earned $20,000 in bounties and two CVEs. 🔗 https://www. bleepingcomputer.com/news/secu rity/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/ # CyberSec # AI # Exploit

A proof-of-concept extension can hijack AI agents in Chrome, Edge, Opera, Perplexity, and Claude. Two CVEs assigned. # Cybersecurity # AI https:// deafnews.it/en/article/bragjac k-a-malicious-extensio

mastodon:infosec-exchangeother10d ago kagi ↗

A proof-of-concept extension can hijack AI agents in Chrome, Edge, Opera, Perplexity, and Claude. Two CVEs assigned. # Cybersecurity # AI https:// deafnews.it/en/article/bragjac k-a-malicious-extension-hijacks-five-ai-agents-in-chromium-browsers

Gal Weizman disclosed BragJack, a PoC where one malicious Chromium extension hijacks embedded AI agents including Gemini Live, Comet, Edge, Opera Neon and Claude in Chrome. The agent browsing context

mastodon:infosec-exchangeother10d ago kagi ↗

Gal Weizman disclosed BragJack, a PoC where one malicious Chromium extension hijacks embedded AI agents including Gemini Live, Comet, Edge, Opera Neon and Claude in Chrome. The agent browsing context and actions become attacker-controlled, making extension trust a critical AI security boundary. # BragJack # BrowserSecurity # AiSecurity https:// cyberworldops.eu/en/bragjack-t urns-browser-extension

🤖 BragJack: a single malicious browser extension can hijack AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome via prompt injection. PoC by Gal Weizman (Forever Security

mastodon:infosec-exchangeother9d ago kagi ↗

🤖 BragJack: a single malicious browser extension can hijack AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome via prompt injection. PoC by Gal Weizman (Forever Security); earned $20k+ in bounties and two CVEs. 🔗 https://www. bleepingcomputer.com/news/secu rity/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/ # AI # InfoSec # CyberSec # Exploi

We gave AI agents browser control, and extensions immediately hijacked them via prompt forcing. Twenty thousand dollars in bounties to prove automation merely scales gullibility. https://www. bleeping

mastodon:infosec-exchangeother8d ago kagi ↗

We gave AI agents browser control, and extensions immediately hijacked them via prompt forcing. Twenty thousand dollars in bounties to prove automation merely scales gullibility. https://www. bleepingcomputer.com/news/secu rity/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/