BragJack Lets Browser Extensions Hijack AI Agents in Five Browsers

Key Takeaways

  • Researcher Gal Weizman showed that ordinary browser extensions could hijack privileged AI browser agents.
  • Affected products were Chrome with Gemini, Edge with Copilot, Opera Neon, Perplexity Comet, and Claude in Chrome.
  • The attack abused the channel between extensions and the agent rather than relying on prompt injection.
  • All five vendors fixed the issues, paid bounties from $600 to $7,000, and Google and Microsoft issued CVEs.
  • No exploitation in the wild was reported.

An Extension With an Agent on a Leash

Browsers are adding AI agents that can read pages, fill forms, and act for the user. BragJack showed that a low-privilege extension could quietly drive those agents. As Dark Reading reported, an extension could keep sending instructions until the agent agreed to do almost anything.

What We Know

Gal Weizman, an agentic browser researcher at Forever Security, published BragJack on September 16, 2026 after coordinated disclosure. The research covered Google Chrome with Gemini, Microsoft Edge with Copilot, Opera Neon, Perplexity Comet, and Claude in Chrome.

All five companies confirmed the issues and paid bug bounties ranging from $600 to $7,000. Google assigned CVE-2026-0628 and Microsoft assigned CVE-2026-55945. The issues have been resolved, as Cybersecurity News also reported, and no exploitation in the wild has been reported.

What Could Happen

Browsers separate untrusted extensions from privileged components, and agentic features should sit on the privileged side. BragJack found ways across that boundary. In Chrome, modified network requests could substitute malicious JavaScript into the agent's flow. In Edge, two weaknesses were chained through a race condition between the agent's Think and Do modes.

Once an extension can talk to the agent, it can issue repeated commands without the user seeing them. The agent then acts with the user's signed-in sessions, which can mean reading email, accessing business apps, or submitting forms. Because extensions are common and often over-permissioned, the potential audience ran into the hundreds of millions.

Why It Matters

Agentic browsers add a powerful actor to the most exposed application on the endpoint. BragJack shows the agent's trust boundary must hold not only against web content but against other software on the same machine.

For enterprises, it raises the stakes of extension hygiene. An extension that once could only read a page may now be able to direct an agent that can act across every logged-in service.

PointGuard AI Perspective

AI agents inside the browser need the same governance as any other agent. PointGuard AI Agentic Endpoint Security discovers agentic browsers and AI features on managed devices, maps them against installed extensions, and applies policy to what browser agents can access.

PointGuard AI Intelligent Guardrails evaluate instructions and actions in real time, flagging repeated or unusual commands that do not match the user's intent. As browsers become agents, trustworthy adoption depends on controls that verify who is really giving the orders.

Incident Scorecard Details

Total AISSI Score: 5.5/10

Criticality: 7, Hijacked agents could act within users' signed-in sessions across email and business apps. AISSI weighting: 25%

Propagation: 7, Five major browsers and AI assistants were affected, reaching hundreds of millions of potential users. AISSI weighting: 20%

Exploitability: 4, Proof-of-concept attacks were demonstrated, with no exploitation in the wild. AISSI weighting: 15%

Supply Chain: 5, Risk arose from third-party browser extensions interacting with vendor AI features. AISSI weighting: 15%

Business Impact: 4, All vendors fixed the issues quickly, with no confirmed harm. AISSI weighting: 25%

Sources

Third-Party Sources

PointGuard AI Sources

AI Security Severity Index (AISSI)

0/10

Threat Level

Criticality

7

Propagation

7

Exploitability

4

Supply Chain

5

Business Impact

4

Scoring Methodology

Category

Description

weight

Criticality

Importance and sensitivity of theaffected assets and data.

25%

PROPAGATION

How easily can the issue escalate or spread to other resources.

20%

EXPLOITABILITY

Is the threat actively being exploited or just lab demonstrated.

15%

SUPPLY CHAIN

Did the threat originate with orwas amplified by third-partyvendors.

15%

BUSINESS IMPACT

Operational, financial, andreputational consequences.

25%

Watch Incident Video

Learn More

Use Cases

Glossary

Products

Blogs

Subscribe for updates:

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.