Tech News
← Home  ·  All topics

Bragjack

2 GoKawiil briefs on this topic

BragJack flaw let malicious extensions hijack AI browser agents in five browsers

Security researcher Gal Weizman of Forever Security found that a single malicious browser extension could take over AI assistants embedded in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome, using Chromium's declarativeNetRequest feature to manipulate trusted network traffic without any user interaction. The technique, called BragJack, earned Weizman over $20,000 in bug bounties across the five vendors and generated two CVEs, with Google and Microsoft having already patched the issues.

New 'BragJack' Exploit Hijacks Built-In Browser AI Assistants

Security researchers have identified a novel attack technique, dubbed BragJack, that exploits agentic AI assistants embedded directly in web browsers. The attack allows malicious actors to manipulate these assistants into accessing sensitive user information, performing unauthorized actions, and exfiltrating data without the user's knowledge.