Security researcher Gal Weizman of Forever Security revealed BragJack, a new attack technique that can hijack AI assistants inside popular browsers through a single malicious extension. The findings affected Google Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome, and led to two CVEs and bug bounty rewards from multiple vendors. #BragJack #GalWeizman #ForeverSecurity #GoogleChrome #GeminiLive #PerplexityComet #MicrosoftEdge #OperaNeon #ClaudeinChrome #CVE-2026-0628 #CVE-2026-55945
Keypoints
- BragJack hijacks browser AI assistants through a malicious extension already installed on the victim’s browser.
- The attack abuses Chromium’s declarativeNetRequest to tamper with trusted browser traffic and inject code.
- Chrome, Comet, Edge, Opera Neon, and Claude in Chrome were all shown to be vulnerable in different ways.
- The technique can expose sensitive data, browsing history, screenshots, and even let agents act on behalf of the user.
- Google and Microsoft fixed their assigned issues, and users should remove untrusted extensions and keep browsers updated.