BragJack PoC Highlights Extension Risk to AI Browser Agents
Medium · BleepingComputer ·
Key points
- BragJack is a proof-of-concept attack against AI browser assistants.
- It reportedly affects Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome.
- The method, Prompt Forcing, uses one malicious extension rather than multiple exploits.
- The research earned more than $20,000 in bounties and two CVEs; CVE IDs were not provided.
- No active exploitation in K-12 was described, so treat this as a design-risk warning.
Security researcher Gal Weizman of Forever Security disclosed a proof-of-concept called BragJack that shows how a single malicious browser extension can hijack AI assistant features. BleepingComputer reports that the attack targets AI agents in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The technique is called Prompt Forcing. It reportedly earned more than $20,000 in bounties and two CVEs, although the CVE identifiers were not included in the provided facts.
The concern for schools is that browser-based AI assistants are often given broad access to what a user sees and does in the browser. They may read page content, interact with tabs, or perform actions on a user's behalf. Extensions already run with trusted browser privileges, so a malicious extension that can influence an AI assistant could turn that assistant into a relay for attacker-controlled prompts or data collection. This affects any managed or unmanaged device where staff or students use these browsers and AI features.
This is currently a proof-of-concept, not evidence of an active campaign against K-12 organizations. The medium severity reflects that an attacker would still need a user to install a malicious extension. However, the risk could rise if the proof-of-concept is weaponized or if affected vendors do not fully block the behavior. The two reported CVEs suggest vendor acknowledgment, but administrators should verify the CVE IDs and affected versions directly before making decisions.
For now, treat this as a warning about browser extension governance and AI assistant exposure. Review which AI browser features are allowed on managed devices, limit extension installation, and watch for vendor patches or advisories tied to BragJack. If high-value data or administrative sessions are involved, consider stricter separation or temporary restrictions until more details are available.
What to do now
- Inventory browser AI assistant use and installed extensions across managed Chrome, Edge, Opera, and related browsers, then remove unapproved or unknown extensions.
- Enforce extension allowlisting or blocklisting through browser management policies, and disable developer mode or sideloading where possible.
- Patch browsers and AI assistant components promptly, and monitor vendor advisories for the two reported CVEs once their identifiers are published.
- Restrict AI assistant access to sensitive pages, sessions, or administrative consoles using available browser policies and separate profiles.
- Train staff and students to avoid extensions that request broad permissions or interact with AI sidebars, especially from untrusted sources.
- Monitor for unexpected extension installations and anomalous AI assistant behavior, and review logs for prompt-injection or data-exfiltration indicators.
- Reassess risk and consider temporarily disabling AI browser agents in high-risk environments if exploitation or weaponization is reported.
Original source
Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.