BlackTree Security · Infrastructure · Automation · AI

One Browser Extension Can Secretly Command Five AI Assistants

The dangerous instruction did not arrive through a poisoned webpage. It came from a browser extension using the same permissions many users associate with ad blockers and content tools, then crossed into a far more powerful AI assistant.

Security researcher Gal Weizman calls the technique BragJack. A single proof-of-concept extension was adapted to hijack AI agents in Chrome Gemini Live, Perplexity Comet, Microsoft Edge Copilot Actions, Opera Neon and Claude in Chrome. Depending on the product, the demonstrated effects included local-file access, screenshots, browsing data, camera or microphone activation and authenticated actions.

The extension forced the prompt through a trusted channel

BragJack is not ordinary prompt injection. The extension did not hide instructions in untrusted page content and hope the model followed them. It abused product-specific communication paths so the agent received attacker-authored commands from a context it treated as trusted. Weizman describes this as prompt forcing.

The research identifies the Chrome finding as CVE-2026-0628, scored 8.8 and fixed in Chrome 143.0.7499.192. A related race condition in Edge is tracked as CVE-2026-55945 and fixed in Edge 150.0.4078.48. Perplexity, Opera and Anthropic remediated the demonstrated behaviours without public CVE identifiers in the reviewed sources.

Five fixes point to one architectural problem

Each product failed differently. Chrome allowed request rewriting and script redirection around its privileged agent view. Edge exposed a race around a tool-enablement action. Other products trusted testing, application or extension messaging paths that an installed extension could reach. The common problem is the boundary between ordinary extension capability and an agent that can act with the user’s authenticated context.

  • Inventory extensions across managed browsers, including sideloaded and developer-mode installations.
  • Review requests for broad site access, request modification, debugger or scripting permissions as privileged access decisions.
  • Update Chrome, Edge and the affected agentic-browser products to builds containing the vendor remediations.
  • Separate experimental agent browsers from privileged administration, finance and sensitive data workflows.
  • Monitor unexpected AI-agent actions such as file reads, screenshot capture, camera or microphone access and navigation to unfamiliar destinations.
  • Require a fresh security review when an existing extension gains new permissions or changes ownership.

The research does not establish a malicious campaign using BragJack, and installing an attacker-controlled extension remains a prerequisite. That prerequisite is not trivial, but browser extensions are already a mature supply-chain and social-engineering target. The significance lies in what the same foothold can now reach.

The fixes for CVE-2026-0628 and CVE-2026-55945 close two implementations. BragJack’s wider lesson is that an assistant able to browse, read and act should not inherit trust merely because a message appears to originate inside the browser.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *