BragJack lets one malicious extension hijack AI agents in Chrome, Edge, Comet, Opera Neon and Claude in Chrome
Forever Security's Gal Weizman earned more than $20,000 in bounties and two CVEs; Google and Microsoft have fixed their flaws, and no user interaction is needed once the extension is installed.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
Security researcher Gal Weizman of Forever Security has disclosed an attack technique, named BragJack, that hijacks the AI assistants built into popular browsers using a single malicious browser extension, BleepingComputer reports. The proof of concept was demonstrated against five Chromium-based browsers or assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon and Anthropic's Claude in Chrome. The research produced two CVEs and earned more than $20,000 in bug bounties across the five vendors, with individual awards ranging from $600 to $7,000. The attack requires the malicious extension to already be installed in the victim's browser. Once it is, Weizman showed the abuse can run without any user interaction, letting the extension control the AI browser agent and misuse the agent's existing privileges to read sensitive information or take actions on the victim's behalf. Google and Microsoft have resolved the flaws assigned to them. Weizman describes these systems as having a brain and a body: the model interprets instructions and decides what should happen, while a privileged browser component carries out the actions, such as accessing tabs, reading page content, taking screenshots or interacting with websites. BragJack targets that trusted body rather than the model. The finding affects anyone running an agentic browser assistant alongside third-party extensions, and it shows that permission boundaries designed for ordinary extensions do not yet account for agents that can act with the user's authority.