Crypto Ticker:
sysadmin from Cyber Security News

BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers

Guru Baran
Saturday at 03:05
4 Views
0 Comments
BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers

A new attack technique dubbed “BragJack” allows a malicious browser extension to seize trusted communication channels used by AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. Rather than bypassing model guardrails or hiding instructions inside web content, the proof-of-concept attacks directly supplied commands to privileged browser components, turning an assistant into a tool for theft and unauthorized actions. Forever Security researcher Gal Weizman demonstrated the technique across all five Chromium-based environments using one extension with browser-specific rules. The extension primarily used content scripts and the declarativeNetRequest API (DNR), which can modify network traffic. Commonly...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!