One Extension Hijacked the AI Inside Five Browsers — No Prompt Injection Required

On September 16, Gal Weizman of Forever Security published BragJack, a technique that hijacks the built-in AI assistants of five Chromium-based browsers with a single malicious extension: Gemini in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome. The vendors paid out more than $20,000 in bounties — $7,000 each from Google and Perplexity, $5,000 from Microsoft, $900 from Opera, $600 from Anthropic — and two CVEs were assigned. Every attack runs with zero clicks once the extension is installed.

The detail that should unsettle agent deployers: Weizman says he did not bypass any model guardrail and did not use prompt injection at all. He found something he considers worse, and gave it a name — Prompt Forcing. Where prompt injection sneaks malicious instructions into content the agent already reads, Prompt Forcing hands the agent an entire prompt plus follow-up instructions outright, and the agent converts them into legitimate browser actions using privileges it already holds. The attack is not carried out by malware. It is carried out by the trusted assistant, on instruction.

One extension, one primitive, five agents

The same extension worked against all five targets because all five share the same architectural shape and the same weak seam. Weizman frames these systems as a “brain” (the model, usually server-side, deciding what to do) and a “body” (a privileged browser component that screenshots tabs, reads content, touches local state, and acts on websites). The seam is that the body trusts web traffic and pages that extensions are allowed to manipulate — via Chromium’s declarativeNetRequest (DNR) API, which lets an extension rewrite response headers and redirect resources.

The Chrome attack is the cleanest illustration. Extensions are blocked from touching the privileged chrome://glic component or injecting scripts into Google’s Gemini site — but DNR rules could still intercept requests made by the embedded Gemini web app. Weizman weakened security headers and redirected a JavaScript resource, landing code execution inside the Gemini context and speaking directly to Chrome’s privileged AI component instead of going through Gemini’s normal request flow. His impact table credits the Chrome attack with local file access, screenshots, browser-profile leakage, and potential camera and microphone reach. Google assigned CVE-2026-0628 and has fixed it.

The agentic browsers fall further

Against Comet and Edge the payoff escalates from reading data to driving the agent, because those agents can act on websites rather than merely observe them. In Comet, the browser’s built-in agent extension trusted several Perplexity domains — including a testing domain that lacked the protections of the primary site. Weizman removed a redirect to that domain with DNR, loaded it, and injected a content script able to converse with the built-in agent. The loot: browsing history, screenshots, local files, and the ability to issue the agent instructions. His demonstration forced the agent to open Perplexity, summarize the victim’s emails, and exfiltrate the summary to another address.

Edge was supposed to be structurally resistant: Microsoft had split its agent into “Think” and “Do” modes precisely so it could not take arbitrary instructions and arbitrary actions at the same time. Weizman found a race condition that briefly drops the restriction while forcing a prompt, then restores the action capability before the agent re-checks its state — Think and Do reunited in the gap. Microsoft assigned CVE-2026-55945 and has resolved it. Similar flaws fell in Opera Neon and in Claude in Chrome, which is itself an extension rather than a browser — a reminder that the “browser boundary” here is whatever the agent trusts, not whatever the installer is called.

This is a pattern, not an incident

BragJack slots into a lineage this site has been tracking. Unit 42 showed Chrome’s Gemini Live panel could be hijacked for camera and microphone access; ClaudeBleed showed Claude for Chrome trusting an origin instead of the calling script; Weizman himself previously reported, from his time at Manifold Security, that Claude for Chrome executed built-in AI workflows on synthetic clicks without verifying a real user — code he says was still reproducible eight releases later. Each finding is a different door into the same room: a privileged agent that cannot reliably tell who is driving it. And the PromptSnatcher campaign already proved that extensions with ad-blocker-level permissions will quietly intercept AI chats at scale — BragJack is what happens when the thing being intercepted can also act.

The endpoint-defense implication is the one Weizman stresses and the one worth repeating: the final malicious action is performed by legitimate software. An EDR watching for malicious code sees an extension doing things extensions are allowed to do, and an assistant doing things assistants are supposed to do. Detection has to move up a level — to which principal authored the instruction, not which binary executed it.

What to do

  • Update all five browsers now, and treat extensions as agent attack surface. Audit installed extensions, remove anything unrecognized or unused, and treat “read and change all your data on all websites” permission prompts as the equivalent of handing over your assistant — because that is now literally what they can mean.
  • Separate the agent’s privileges from the user’s browsing. Do not run built-in browser agents in the same profile that holds email, admin consoles, and SSO sessions unless you have modeled the extension-to-agent path. A dedicated profile with minimal sessions shrinks what Prompt Forcing can reach.
  • Demand instruction provenance, not just content filtering. Guardrails that scan what the agent reads do nothing against an attacker who writes the prompt directly. Ask vendors whether their agent verifies the origin of instructions and binds privileged actions to real user gestures — and whether synthetic events are rejected.
  • Monitor the assistant, not just the endpoint. Log what browser agents access and instruct: file reads, screenshot calls, outbound messages composed from mailbox content. The Comet email-summarization demo is your detection scenario — an agent reading mail it was never asked to read, then sending the result somewhere new.
  • Track the two CVEs in your inventory. CVE-2026-0628 (Chrome) and CVE-2026-55945 (Edge) are the assigned identifiers; confirm fixed builds are deployed, but do not treat the absence of a CVE on the other three targets as absence of risk — the technique, not the identifiers, is the finding.

The uncomfortable arithmetic: one extension, five assistants, zero clicks, ad-blocker permissions — and the model’s safety training never even enters the picture, because nobody attacked the model. They attacked the plumbing around it. Every organization deploying browser agents just inherited a new trusted insider: the assistant itself, taking orders from anyone who can load a web page it trusts.

Sources: