BragJack PoC Shows One Extension Can Hijack Major Browser AI Assistants

Medium · BleepingComputer ·

Key points

  • BragJack is a proof-of-concept by Gal Weizman of Forever Security.
  • It uses one malicious browser extension to hijack AI assistants via a technique called Prompt Forcing.
  • Affected environments include Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome.
  • The research earned over $20,000 in bug bounties and produced two CVEs, though IDs were not provided.
  • No active exploitation, affected versions, or threat actors were named in the source facts.

Gal Weizman, a security researcher at Forever Security, unveiled BragJack, a proof-of-concept exploit whereby one harmful browser extension takes control of AI assistants. This method, known as Prompt Forcing, aims at AI assistant integrations within Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The work yielded over $20,000 through bug bounty rewards and led to two CVEs; however, the information currently available does not specify the CVE identifiers, impacted versions, threat actor identities, or dates of exploitation.

The significance is the trust boundary. Browser extensions already run with broad permissions, and AI assistants add a new channel that can read page content, act on user intent, and sometimes access connected services. If one extension can manipulate prompts or assistant behavior, it may bypass assumptions that the assistant is isolated from other browser components. This is especially relevant in K-12 and government environments where staff use browsers for email, student information systems, and cloud productivity.

Because BragJack is described as a proof-of-concept, there is no public evidence of active exploitation in the fact set. Still, the affected list covers widely used browsers and emerging AI browser products, so the attack surface is broad. The lack of version details means administrators should not assume a specific build is safe or vulnerable; instead, treat extension and AI assistant permissions as a governance issue.

What to watch: vendor advisories and CVE publications tied to the two referenced CVEs, updates to Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome, and any signs of malicious extension behavior. Defenders should monitor for unexpected extension installs, permission changes, and assistant actions that do not match user intent. The medium severity reflects a credible research finding without confirmed in-the-wild exploitation.

What to do now

  1. Inventory browser extensions across managed endpoints and remove unapproved or unused extensions, especially those with broad host permissions.
  2. Enforce an extension allowlist via enterprise policy in Chrome and Edge, and apply equivalent controls for other browsers; block sideloaded or developer-mode extensions.
  3. Review and restrict AI assistant permissions, including access to page content, clipboard, downloads, and connected accounts; disable assistants where they are not required.
  4. Apply browser and extension updates promptly, and monitor vendor advisories for the two CVEs and any BragJack-related fixes.
  5. Monitor logs and endpoint detection tools for suspicious extension installation, permission escalation, and anomalous AI assistant actions.
  6. Train staff to avoid installing unknown extensions and to report unexpected assistant behavior or potential data exposure.
  7. Consider isolating sensitive workflows from AI-enabled browsers until vendor mitigations and configuration controls are confirmed.

Original source

BleepingComputer

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news