BragJack Attack Lets Browser Extensions Hijack AI Agents Across Chrome, Edge and Comet
A newly disclosed BragJack is a browser-extension attack technique that can hijack built-in AI assistants across five AI-enabled browsers.
The research demonstrates how a single malicious browser extension could allegedly abuse trusted communication paths between cloud-hosted AI models and privileged browser agents, enabling unauthorized commands, sensitive-data access, and browser-level actions.
Forever Security researcher Gal Weizman reported that BragJack affected Gemini Live in Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome.
BragJack Attack Lets Browser Extensions Hijack AI Agents
The vulnerabilities were disclosed to vendors through responsible channels and generated bounty awards from Google, Microsoft, Perplexity, Opera, and Anthropic. The findings include CVE-2026-0628 and CVE-2026-55945.