Security researcher Gal Weizman of Forever Security has disclosed BragJack, a proof of concept attack technique that hijacks AI assistants built into popular browsers using nothing more than a single malicious extension already installed on the victim’s machine.
The technique was demonstrated against five Chromium based browsers or browser assistants: Google Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic’s Claude in Chrome. The disclosure earned more than $20,000 in bug bounties across the five vendors, with individual payouts ranging from $600 to $7,000, and resulted in two CVEs. Google and Microsoft have both patched the flaws assigned to them.
How the attack works
Weizman describes modern AI browser integrations as having a “brain” (the AI model that decides what to do) and a “body” (a privileged browser component that carries out actions like reading tabs, taking screenshots, or interacting with sites). The core problem is that browser extensions can manipulate the web traffic and pages these privileged components implicitly trust.
A single extension using Chromium’s declarativeNetRequest (DNR) functionality, which lets extensions modify network responses and redirect resources, was enough to compromise all five targets. In Chrome, although extensions cannot directly touch the privileged chrome://glic component or inject scripts into Gemini’s site, DNR rules could intercept requests from the embedded Gemini web app. By weakening security headers and redirecting a JavaScript resource, Weizman ran code inside the Gemini context that communicated directly with Chrome’s privileged AI component, bypassing Gemini’s normal request flow. He says the resulting access could reach local files, web content, screenshots, and potentially the camera and microphone. Google assigned CVE-2026-0628 and paid a $7,000 bounty for the finding.
From reading data to controlling agents
Attacks against agentic browsers such as Perplexity Comet and Opera Neon went further, since their agents can act on websites rather than just read them. In Comet, Weizman found the built-in agent trusted several Perplexity domains, including a testing domain lacking the same protections as the primary site. Removing a redirect via DNR let him load that domain and inject a script able to command the agent, gaining access to browsing history, screenshots, local files, and the ability to issue instructions. He demonstrated forcing the agent to visit Perplexity, summarize the victim’s emails, and send the results to an outside address.
Microsoft Edge split its agent into separate “Think” and “Do” modes to prevent it from receiving instructions and acting on them simultaneously. Weizman found a race condition that briefly disables this restriction while forcing a prompt, then re-enables action capability before the agent verifies its state. Microsoft assigned CVE-2026-55945 to this issue. Similar flaws were shown against Opera Neon and Claude in Chrome, the latter itself being a browser extension rather than a standalone browser.
The disclosure follows prior findings against Claude for Chrome, including a weakness where the extension executed AI workflows on synthetic clicks without verifying real user interaction, and an earlier flaw dubbed ClaudeBleed in which the extension trusted the claude.ai origin without checking what script was actually driving it.
