Proof‑of‑Concept ‘BragJack’ Exploits Browser Extensions to Hijack AI Assistants
A new proof‑of‑concept attack dubbed BragJack demonstrates that a single malicious browser extension can take control of several AI chat assistants embedded in popular web browsers.
The technique, developed by security researcher Gal Weizman of Forever Security, targets extensions for Chrome, Edge, Opera Neon, the Perplexity Comet service, and the Claude model when run in Chrome, injecting malicious prompts that redirect the AI’s output.
BragJack relies on a prompt‑forcing method that subtly modifies the instructions an AI agent receives, causing it to execute unintended actions or disclose information it would normally protect. By leveraging the same extension across multiple platforms, the attack showcases how a small piece of code can compromise a wide range of AI‑driven features.
The discovery earned more than $20,000 in bug‑bounty payouts and prompted the issuance of two separate CVE identifiers, underscoring the severity of the underlying flaw in the extension permission model.
AI assistants are increasingly bundled into browsers to provide on‑the‑fly assistance, from drafting emails to answering queries. This integration expands the attack surface, as extensions—often granted broad privileges—can serve as a conduit for malicious prompt injection.
Browser vendors have begun reviewing the findings and are expected to release patches that tighten extension sandboxing and limit the ability of third‑party code to alter AI prompt streams. Security experts advise users to install extensions only from trusted sources and to monitor updates closely as the ecosystem adapts to the emerging threat.
Comments (0)
Be the first to comment.
Join the discussion