BragJack attack hijacks browser AI agents through malicious extensions
Discovered by Forever Security's Gal Weizman, the BragJack proof-of-concept attack uses a single malicious extension to hijack AI assistants across Chrome, Edge, Perplexity, and Claude.

The rapid integration of artificial intelligence into everyday software has opened up fresh attack vectors for cybercriminals. A new proof-of-concept attack dubbed BragJack, created by Gal Weizman of Forever Security, highlights the growing security risks surrounding AI agents operating directly within web browsers.
BragJack specifically targets AI assistants embedded in popular platforms like Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. By leveraging a technique known as Prompt Forcing via a single malicious extension, the attack demonstrates how third-party components can subvert browser-based AI models and manipulate user interactions.
The security implications of this research have been widely recognized within the industry, earning the researcher over $20,000 in bug bounties and resulting in the assignment of two CVEs. Such findings emphasize that current permission models in browsers are often inadequate when dealing with powerful LLM-driven assistants.
For the technology community and digital users in Central Asia and beyond, this development underscores the critical need for caution when installing browser extensions. Because extensions frequently request broad permissions, malicious actors can easily exploit them to compromise sensitive data processed by AI tools.
As AI agents become more deeply integrated into our daily workflows, tech giants and browser vendors must enforce stricter isolation boundaries. Until robust defenses are standard across all platforms, users should exercise strict digital hygiene by limiting extensions to trusted, verified sources only.



