BragJack attacks hijack AI browser agents through malicious extensions
Researcher Gal Weizman disclosed the BragJack technique, allowing a single malicious extension to hijack AI assistants in five Chromium-based browsers: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome. Over $20,000 in bug bounties were paid and two CVEs issued; Google and Microsoft have already fixed the vulnerabilities.
- Attack affected Gemini Live, Comet, Edge, Opera Neon, and Claude in Chrome
- Over $20,000 paid in bug bounties, amounts from $600 to $7000
- CVE-2026-0628 in Chrome and CVE-2026-55945 in Edge issued
- Requires an already installed malicious extension, then no user action
Read next
Security