Sophia
Hart

BragJack Attack Exposes Agentic Browser AI to Hijacking

Sophia Hart

Sep 18, 2026

6 min read

bragjack attack

TL; DR

  • Gal Weizman of Forever Security found BragJack, an attack that hijacks browser AI agents without prompt injection.
  • BragJack affects Chrome with Gemini, Edge with Copilot, Opera Neon, Perplexity Comet, and Claude in Chrome.
  • Google and Microsoft issued CVE-2026-0628 and CVE-2026-55945. Opera, Perplexity, and Anthropic patched the flaw and paid bounties without assigning dedicated CVEs.
  • Any device with an installed extension is at risk, since attackers could access files, screenshots, cameras, microphones, and authenticated sessions.

Security researcher Gal Weizman at Forever Security disclosed the BragJack attack. It is a proof-of-concept technique that hijacks AI assistants built into five major browsers. The attack affects Google Chrome with Gemini, Microsoft Edge with Copilot, Opera Neon, Perplexity Comet, and Claude in Chrome.

Weizman found that a malicious browser extension can seize the communication channel between the browser and its AI agent. A compromised extension carries the same risk. The extension can then force the agent to follow attacker prompts. Unlike most AI agent security incidents, BragJack does not require bypassing model guardrails or hiding instructions inside web content.

For enterprise security teams, the BragJack attack matters for one reason. Agentic browsers now hold direct access to files, cameras, microphones, and authenticated business sessions. Any device running an agentic browser with at least one installed extension carries this exposure. Agentic browser security now needs the same governance IT already applies to other endpoint software.

Book a free demo and explore Hexnode today!

How this browser extension attack hijacks an AI Agent

BragJack does not rely on prompt injection, where attackers hide instructions inside content an agent reads. Instead, the flaw lets a browser extension cross the boundary that separates untrusted extensions from the privileged AI agent. Weizman describes the flaw as shared across all five browsers, even though each vendor implemented it differently.

In Chrome with Gemini, the researchers found this path. The extension used Chromium’s declarativeNetRequest (DNR) API, a legitimate capability normally used by ad blockers and content filters to intercept and modify network requests. Chrome blocked script injection into Gemini’s page but allowed extensions to modify the network requests that load Gemini.

  • The researchers used DNR rules to intercept and alter the network requests loading Gemini’s interface, then substituted their own JavaScript through that gap.
  • This gave them control of Gemini’s browser-side component.
  • That control let them take screenshots, read local files, and activate the camera and microphone without any user click.

Chrome Gemini security depended on that one unprotected network-request path. Microsoft Edge Copilot required a longer chain because its defenses were stronger:

  • The researchers used a privileged Microsoft marketing page that could send prompts to the browser agent.
  • They then exploited a race condition between Edge’s Think and Do modes to bypass a network-level defense.
  • These are two distinct mechanisms. The marketing-page privilege and the mode-switch race condition each did separate work in the Edge exploit chain.

Which browsers and vendors were affected

Forever Security contacted all five affected vendors: Google, Microsoft, Opera, Anthropic, and Perplexity. Each vendor confirmed the flaw and paid a bug bounty, ranging from $600 to $7,000. Only Google and Microsoft issued CVEs, CVE-2026-0628 and CVE-2026-55945, for their Chrome and Edge implementations. Opera, Perplexity, and Anthropic patched their flaws and paid bounties without a dedicated CVE. All five companies have since resolved the issues.

Affected Browser AI Assistant Disclosed Attack Path
Google Chrome Gemini Extension modified network requests to inject JavaScript into Gemini’s interface
Microsoft Edge Copilot Extension chained a privileged marketing page with a Think/Do mode race condition
Opera Neon Built-in agent Same extension-to-agent boundary flaw; specific mechanism not publicly detailed
Perplexity Comet Built-in agent Same extension-to-agent boundary flaw; specific mechanism not publicly detailed
Claude in Chrome Claude Same extension-to-agent boundary flaw; specific mechanism not publicly detailed

What an attacker could do once inside

Weizman said the browser agents in his tests would follow instructions from the attacking extension without question. The attacks can also bypass many current endpoint detection and response tools, according to Weizman.

Reported capabilities included:

  • Access sensitive information, such as email correspondence, and leak it to attacker-controlled destinations.
  • Take actions on any website where the user stayed logged in, including destructive changes.
  • Access local files and take screenshots of the browser session.
  • Activate the device camera or microphone without a visible user prompt.

Immediate Steps for Security Teams

Weizman recommends immediate action rather than waiting for further guidance:

  • Update every Chromium-based browser in the organization to the latest patched version.
  • Remove any extension that has not been vetted, is not well known, or is not clearly safe.
  • Export transcripts of each agentic browser’s interactions with its AI provider and review them for suspicious behavior.
  • Evaluate next-generation EDR tools that can intercept agentic browser operations directly on the endpoint.
the cybersecurity blueprint

The Cybersecurity Blueprint

Guide to choosing and implementing the right cybersecurity strategy, backed by key statistics.

DOWNLOAD

Where endpoint management fits into BragJack defense

Hexnode does not detect the BragJack attack itself. It also does not monitor an AI provider’s server-side agent behavior. What it can do is reinforce two of Weizman’s recommended controls at the endpoint level.

Hexnode UEM: Browser and extension governance

  • Enforce OS and application update policies, including Chrome and Edge updates, across managed Windows and macOS devices.
  • Allowlist or blocklist specific Chrome extensions using Browser Settings in Hexnode UEM policy on Windows and ChromeOS, and a Chrome extension configuration profile on macOS.

Hexnode XDR: Endpoint-level containment

  • Investigate suspicious process activity and isolate compromised endpoints on managed Windows and macOS devices.
  • XDR does not read browser extension telemetry or AI provider interaction logs. Teams still need the manual log review Weizman recommends, alongside these endpoint controls.

FAQs

Vendors have patched the specific flaws Weizman disclosed, but new extension-to-agent boundary issues could still emerge. Keep browsers current and review installed extensions regularly.

No. Weizman states the attackers sent prompts directly through a hijacked channel, not hidden inside content the agent reads.

Weizman says these attacks can bypass many current EDR systems. He recommends reviewing AI provider interaction logs and adopting next-generation EDR built for agentic operations.

Conclusion

The BragJack attack shows that agentic browsers create a new class of endpoint risk. Attackers no longer need to bypass AI guardrails when they can hijack the communication channel directly.

Security teams should treat browser extensions as a governed attack surface, not a convenience feature. Combining extension controls, browser patching, and endpoint monitoring narrows the exposure this attack pattern revealed.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.