· 6 min read

One Browser Extension Just Hijacked Five AI Browser Assistants at Once. Anthropic Paid $600 to Find Out How.

A security researcher built one browser extension, wrote browser-specific rules into it, and used it to hijack the built-in AI assistants in five different browsers: Chrome, Edge, Opera, Comet, and Claude in Chrome. No prompt injection, no jailbreak, no tricking the model into ignoring its instructions. The extension just talked directly to the privileged internal channel each browser uses to let its AI agent act on the page, the same channel the browser itself trusts completely. Forever Security's Gal Weizman calls it BragJack, and it's a good reminder that the weakest link in "AI agent security" right now isn't the model.

How BragJack actually works

Every major browser that ships a built-in AI assistant needs some way for that assistant to read the page, click things, and act on your behalf. That requires a trusted internal communication channel between the browser's privileged components and the AI feature. BragJack's insight was that this channel isn't defended the way you'd expect: a malicious extension, using ordinary content scripts and the declarativeNetRequest API that Chrome extensions use all the time to modify network traffic, can intercept or forge messages on that channel and start issuing commands directly.

That matters because it skips the entire category of defense the industry has spent the last two years building. Model providers have gotten meaningfully better at resisting prompt injection, the attack where malicious instructions get embedded in a webpage and trick the AI into doing something the user didn't ask for. BragJack doesn't bother with any of that. It doesn't need the model to be tricked, because it never talks to the model. It talks to the plumbing underneath the model, which trusts the extension because the extension is, as far as the browser is concerned, just another add-on the user installed.

The reported impact varied by product but included reading local files, pulling browser history, taking screenshots, and in some configurations reaching camera or microphone access, depending on what permissions that browser's AI feature already had. None of this required the user to click a malicious link or fall for a phishing page. It required only that the malicious extension be installed, which is a bar a lot of people clear without thinking twice.

The bug bounty numbers tell their own story

Weizman reported the issue to five affected companies: Google, Microsoft, Opera, Anthropic, and Perplexity. All five acknowledged the vulnerability and paid a bounty. Google and Microsoft went further and issued CVEs, CVE-2026-0628 and CVE-2026-55945 respectively. All five have since shipped fixes.

The bounty amounts ranged from Anthropic's $600 up to Google's $7,000. I don't think that gap tells you Anthropic takes the issue less seriously than Google, bounty programs price based on internal severity rubrics and program maturity, not just raw impact, and a wide range across five different companies' independent bug bounty programs is normal. But it's a useful data point if you're trying to gauge how mature the "AI agent in a browser" security model is industry-wide right now: not very, across the board, regardless of which vendor's logo is on it.

What this means if you actually use one of these

If you're still treating your browser's built-in AI assistant as a novelty, this is interesting but not urgent. If you've started using Claude in Chrome, Comet, or one of the others to do real work, book flights, fill out forms, summarize your inbox, the calculus changes. Your attack surface is no longer "the websites I visit plus whatever the AI vendor's guardrails catch." It's every extension you have installed, including ones you added months ago for something unrelated and forgot about.

That's the part I'd actually act on. I went through my own extension list after reading the BragJack writeup and found two I couldn't explain why I still had installed: a PDF viewer I'd replaced with a different tool and a coupon-finder I'm fairly sure I never asked to install in the first place. Neither was malicious as far as I can tell, but "as far as I can tell" isn't a security control, and neither needed the permissions it had.

The honest take

All five vendors patched this specific technique, so BragJack itself is closed. What's not closed is the underlying assumption that a browser vendor's own privileged UI is inherently more trustworthy than a third-party extension running in the same browser, which is the assumption this whole attack class exploits. I'd expect more variations on this theme before the industry settles on a real architectural fix, something closer to how mobile OSes sandbox app permissions individually rather than trusting anything with a "run in this browser" badge.

If you use an AI browser agent for anything beyond casual browsing, do the audit now rather than after the next disclosure: open your extensions list, remove anything you can't immediately explain the purpose of, and check what permissions the ones you keep actually have. It's a fifteen-minute task. Waiting for the next BragJack-shaped headline to prompt you costs more than fifteen minutes if you're wrong about which extensions you trust.

Author

Sources

Stay in the Loop

Get new posts delivered to your inbox. No spam, unsubscribe anytime.

Newsletter coming soon. Set PUBLIC_CONVERTKIT_FORM_ID in .env to activate.

Related Posts