Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
3 clusters · 9 sources · 9 days · First seen · Last updated
Security vulnerabilities in AI agents and assistants
Overview
Security researchers have identified critical vulnerabilities affecting various AI agents and assistants. Initially, researchers at Air discovered ‘Plugin4Shell’, a flaw in the SHA-pinning mechanism used by AI coding agents like Claude Code, Codex, Gemini CLI, and Microsoft Copilot. This vulnerability allows attackers to bypass plugin integrity verification and inject malicious code, posing a ‘zero-click’ threat to developer machines and corporate data. In response, Anthropic and OpenAI issued patches, Google deprecated the affected Gemini CLI, and Microsoft has yet to release a fix. Subsequently, researchers at Forever Security demonstrated ‘prompt-forcing’, a technique where malicious browser extensions can hijack AI assistants integrated into Chromium-based products. This vulnerability affects Gemini Live in Google Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude Chrome extension. By injecting code into trusted web pages, extensions can bypass security boundaries to issue commands. Reported impacts include the ability to read files, capture screens, activate microphones or cameras, and bypass task-execution restrictions. Building on this research, security researcher Gal Weizman of Forever Security identified a specific vulnerability named ‘BragJack’. This flaw allows malicious extensions to exploit the Chromium declarativeNetRequest (DNR) function to manipulate network requests and intercept traffic. This enables an attacker to take control of an AI agent, which can then use its privileges to read content, take screenshots, or interact with web pages without direct user intervention. The discovery resulted in two official CVEs, and both Google and Microsoft have since released patches to address these flaws. Recent findings have expanded the scope of risks to AI coding agents, specifically highlighting ‘conversation history poisoning’. Researchers demonstrated that agentic harnesses often store history in unverified local databases, such as SQLite, allowing attackers to inject fabricated data. This manipulation tricks the AI into following malicious instructions by making them appear as previously agreed-upon states.
Entities
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] Security researcher Gal Weizman discovered a technique to hijack AI assistants via malicious extensions. www.softzone.es
- [○ 1 SOURCE] The vulnerability, named BragJack, affects Google Chrome, Microsoft Edge, Perplexity Comet, Opera Neon, and Claude in Chrome. www.softzone.es
- [○ 1 SOURCE] The attack uses the declarativeNetRequest (DNR) function in Chromium to manipulate network requests. www.softzone.es
- [○ 1 SOURCE] Google and Microsoft have already patched the identified vulnerabilities. www.softzone.es
- [○ 1 SOURCE] The research resulted in two official CVEs and over $20,000 in bug bounty rewards. www.softzone.es
Timeline
-
4 days ago
[TECHNOLOGY] 4 sourcesAI coding agents face critical security vulnerabilitiesResearchers have uncovered major security flaws in AI coding agents like Claude Code and Copilot, including history poisoning and ‘Plugin4Shell’, which could allow attackers to hijack workflows and execute code
-
11 days ago
[TECHNOLOGY] 3 sourcesBragJack vulnerability hijacks AI assistants in major browsersResearcher Gal Weizman discovered BragJack, a vulnerability allowing malicious extensions to hijack AI assistants in Chrome, Edge, and other browsers by manipulating network requests.
-
12 days ago
[TECHNOLOGY] 2 sourcesPlugin4Shell vulnerability affects major AI coding agentsResearchers discovered ‘Plugin4Shell,’ a zero-click vulnerability affecting AI coding agents like Claude Code, Codex, and Copilot, risking unauthorized access to corporate data.
Sources
cybernoz.com · dev.to · dijitaliyidir.com · forkast.news · infoguerra.com.br · softzone.es · spacemoney.com.br · tokenpost.com · yeniyolgazetesi.com
This summary has been updated 2 times: see revision history