BragJack Attack Can Turn a Browser’s Agentic AI Against It

A New Threat Emerges as BragJack Attack Exploits Browser’s Agentic AI, Putting Hundreds of Millions at Risk

A devastating new type of attack has been discovered, capable of hijacking the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data. The proof-of-concept attack, dubbed BragJack, compromises five agentic browser environments: Google Chrome with Gemini, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. This critical vulnerability has been confirmed by multiple companies, including Google and Microsoft, which have issued CVEs for the flaws in their respective browsers.

Gal Weizman, an agentic software and browser vulnerability researcher at Forever Security, discovered the attack. He notes that BragJack didn’t require researchers to bypass AI guardrails or rely on prompt injection techniques, where attackers hide instructions in content that an AI agent is expected to read. Instead, the attack exploits a critical design flaw in how agentic browsers interact with extensions. This allows attackers to hijack the communication channel completely and force prompts into the browser’s built-in agent, making it do whatever they choose.

Weizman explains that BragJack works by sending one prompt after another until the agent gets convinced to do anything. This attack was effective against five of the most popular agentic browsers in the world, making it more than just a single vulnerability instance but a novel type of attack. The manifestation of BragJack in each browser was different, as each had a unique vulnerability; however, the architectural problem exploited across browsers was the same: allowing an untrusted extension to cross a boundary that separates it from a highly privileged AI agent.

This means that any consumer who used any of the five browsers with at least one extension installed was at risk. Weizman estimates this amounts to hundreds of millions of users. The affected companies have since resolved the issues, but not before awarding bug bounties ranging from $600 to $7,000 for the vulnerabilities.

In a particularly disturbing example, researchers used BragJack in Google Chrome/Gemini to take screenshots, access local files, and activate the camera and microphone without user clicks. In Microsoft Edge/Copilot, they had to chain together two weaknesses due to stronger defenses, but ultimately managed to execute malicious actions. The success of BragJack demonstrates yet another way attackers can manipulate AI agents, reinforcing dire warnings from experts over the weekend to rein in AI development.

So what does this mean for you? If you use any of these browsers with extensions installed, it’s essential to update your browser and extension settings as soon as possible. Moreover, be cautious when installing new extensions and regularly review your browser’s privileges and permissions. As AI continues to play a larger role in our digital lives, it’s crucial that we prioritize cybersecurity measures to prevent attacks like BragJack from compromising not only our data but also the very tools designed to protect us.


Source: Dark Reading — 2026-09-16