#27 · Briefing ·

BragJack Attack Hijacks Browser AI Assistants

A newly identified proof-of-concept attack called BragJack bypasses traditional AI guardrails by hijacking communication channels to turn built-in browser assistants against their users.

AI assistants silently taking screenshots?
AI-generated illustration. AI assistants silently taking screenshots?

A newly discovered proof-of-concept attack called BragJack has demonstrated how malicious actors can compromise five major agentic browser environments. According to the research, the attack targets Google Chrome with Gemini, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. Rather than relying on traditional AI-based attack vectors like prompt injection or guardrail bypasses, this method hijacks the underlying communication channel to force prompts directly into the AI agent. In response to these findings, Google patched the Chrome vulnerability, CVE-2026-0628, in Chrome version 143.0.7499.192 in January 2026. Microsoft subsequently addressed its medium-severity Edge vulnerability, CVE-2026-55945, by deploying version 150.0.4078.48 on July 2, 2026.

Security researcher Gal Weizman of Forever Security is credited with discovering the BragJack attack. Weizman's research team at Forever Security received a total of $20,500 in bug bounties from the affected companies for disclosing the vulnerabilities. According to the researchers, the individual payouts consisted of $7,000 from Google, $7,000 from Perplexity, $5,000 from Microsoft, $900 from Opera, and $600 from Anthropic.

This vulnerability matters because it allows attackers to bypass standard AI guardrails entirely to extract sensitive user information. The proof-of-concept demonstrated that hijacked agents could silently take screenshots of private data, steal local files, activate cameras and microphones without consent, and exfiltrate data. The severity of the impact depended on how deeply the AI was integrated into the browser environment. Perplexity Comet was evaluated as the worst-case scenario because it was built as a fully AI-driven browser, giving its agent broad powers. Conversely, Claude in Chrome was evaluated as the mildest case because it operates as a browser extension, meaning the attack involved one extension abusing another rather than abusing the core browser itself.

The affected technology companies responded by validating the research and issuing financial rewards to Forever Security. Google classified its respective Chrome vulnerability, CVE-2026-0628, as a high-severity flaw with a CVSS score of 8.8. Microsoft classified its Edge vulnerability, CVE-2026-55945, as a medium-severity flaw with a CVSS score of 4.2. Both companies successfully deployed security patches to resolve the communication hijacking vulnerabilities in their respective browser platforms.

While major platforms have successfully deployed fixes to secure their users, it remains unclear how many smaller, niche agentic browsers remain vulnerable to similar communication hijacking techniques. The extent to which other developers have audited their internal AI communication channels against the BragJack methodology is currently unknown.

Sources

Verified claims

Original reporting: https://www.darkreading.com/cyberattacks-data-breaches/bragjack-attack-can-turn-a-browser-s-agentic-ai-against-it

Written by The Quiet Search. Method: /about.

Related

Comments

Plain text only. New comments stay hidden until a person reviews them.