Kryptovalutaticker:
sysadmin från Cyber Security News

BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers

Guru Baran
Saturday at 03:05
5 Visningar
0 Kommentarer
BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers

A new attack technique dubbed “BragJack” allows a malicious browser extension to seize trusted communication channels used by AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. Rather than bypassing model guardrails or hiding instructions inside web content, the proof-of-concept attacks directly supplied commands to privileged browser components, turning an assistant into a tool for theft and unauthorized actions. Forever Security researcher Gal Weizman demonstrated the technique across all five Chromium-based environments using one extension with browser-specific rules. The extension primarily used content scripts and the declarativeNetRequest API (DNR), which can modify network traffic. Commonly...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!