BragJack attacks hijack AI browser agents through malicious extensions

Refract AI Intelligence Digest

BLUF

Malicious browser extensions can hijack integrated AI assistants across multiple platforms via prompt forcing.

NEWS

Security researcher Gal Weizman demonstrated BragJack, which targets AI agents in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude using a single malicious extension. The attack leverages prompt forcing to compromise these tools and has already resulted in over $20,000 in bounties and two CVEs.

Why I Care

This vulnerability undermines trust in browser-integrated AI tools, potentially allowing attackers to exfiltrate data or execute commands through compromised assistants. Any user relying on these AI agents for sensitive tasks faces increased risk of manipulation without traditional malware detection.

Next Steps

Users should audit and remove untrusted browser extensions immediately, while security teams must monitor extension permissions affecting AI processes. Browser vendors need to prioritize patching prompt injection vulnerabilities in their AI agent architectures.

BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.