SEPTEMBER 19, 2026
Subscribe
Global Press Media · World Report
Technology

Proof‑of‑Concept ‘BragJack’ Attack Shows One Malicious Extension Can Hijack Multiple Browser‑Based AI Assistants

Proof‑of‑Concept ‘BragJack’ Attack Shows One Malicious Extension Can Hijack Multiple Browser‑Based AI Assistants

Researchers have unveiled a proof‑of‑concept exploit named BragJack, which shows that just one rogue browser extension is capable of commandeering multiple AI chat assistants built into widely used browsers.

Created by security analyst Gal Weizman of Forever Security, the method targets extensions on Chrome, Edge, Opera Neon, the Perplexity Comet service, and the Claude model operating in Chrome, inserting harmful prompts that steer the AI’s responses.

The exploit uses a prompt‑forcing technique that gently alters the commands an AI receives, prompting it to perform unintended tasks or reveal data it would otherwise safeguard. Deploying the identical extension on various platforms illustrates how a modest snippet of code can jeopardize a broad spectrum of AI‑powered functionalities.

The find netted over $20,000 in bug‑bounty rewards and triggered the assignment of two distinct CVE numbers, highlighting the critical nature of the vulnerability in the extension permission architecture.

Browsers are progressively embedding AI assistants to deliver real‑time help, such as composing emails or answering questions. This coupling widens the attack surface, because extensions—frequently given extensive rights—can act as a pathway for malicious prompt injection.

Vendor teams are now examining the results and are slated to roll out updates that reinforce extension sandboxing and curb third‑party code from tampering with AI prompt flows. Experts recommend that users install extensions solely from reputable sources and keep a close eye on updates as the ecosystem responds to this new threat.

Editorial Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related