< Back to all clusters
[TECHNOLOGY] · Spain · 3 sources

started · updated

BragJack vulnerability hijacks AI assistants in major browsers

Security researcher Gal Weizman of Forever Security has identified a vulnerability known as BragJack, which allows malicious browser extensions to hijack integrated AI assistants. The technique affects several major platforms, including Google Chrome, Microsoft Edge, Perplexity Comet, Opera Neon, and Claude in Chrome.

Once a malicious extension is installed, it can exploit the Chromium declarativeNetRequest (DNR) function to manipulate network requests and intercept traffic. This allows the attacker to take control of the AI agent, which can then use its existing privileges to read content, take screenshots, or interact with web pages on behalf of the user without direct intervention.

In recognition of the discovery, Weizman received over $20,000 in bug bounty rewards. The research has resulted in the issuance of two official CVEs, and both Google and Microsoft have already released patches to address the flaws.

Entities

Anthropic · Claude · Forever Security · Gal Weizman · Google · Google Chrome · Microsoft · Microsoft Edge · Perplexity

Claims

What the coverage asserts, and how many sources carry each claim.

  • [○ 1 SOURCE] The vulnerability, named BragJack, affects Google Chrome, Microsoft Edge, Perplexity Comet, Opera Neon, and Claude in Chrome. www.softzone.es
  • [○ 1 SOURCE] Google and Microsoft have already patched the identified vulnerabilities. www.softzone.es
  • [○ 1 SOURCE] The attack uses the declarativeNetRequest (DNR) function in Chromium to manipulate network requests. www.softzone.es
  • [○ 1 SOURCE] The research resulted in two official CVEs and over $20,000 in bug bounty rewards. www.softzone.es
  • [○ 1 SOURCE] Security researcher Gal Weizman discovered a technique to hijack AI assistants via malicious extensions. www.softzone.es