< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

BragJack attack allows malicious extensions to hijack AI agents

Security researcher Gal Weizman of Forever Security has identified a new attack technique called “BragJack” that allows malicious browser extensions to hijack AI assistants. The vulnerability affects five major Chromium-based environments, including Chrome, Edge, Opera Neon, Comet, and Claude in Chrome.

Unlike traditional prompt injection, which embeds hostile instructions within web content, BragJack utilizes “prompt forcing.” The attack exploits the “split-brain” architecture common to modern agentic browsers, where an AI model hosted on a vendor website communicates with a privileged execution engine inside the browser. By using content scripts and the declarativeNetRequest API, a rogue extension can intercept or spoof trusted communication channels, issuing commands directly to the browser engine as if they originated from the official vendor.

Because the attack targets the authorization and message-channel trust before the AI evaluates the intent, model-level safety filters and reasoning capabilities are unable to prevent the breach. The execution engine, which has access to sensitive data such as emails, banking portals, and local files, treats the injected commands as legitimate. All five affected platforms have since been patched.

Entities

Forever Security · Gal Weizman · Google Chrome · Microsoft Edge · Opera