← Blog · · df00tech

BragJack Proof-of-Concept Shows How a Single Malicious Extension Can Hijack AI Browser Agents

security-news technique

What happened

Security researcher Gal Weizman of Forever Security disclosed a proof-of-concept attack technique called BragJack, which uses a malicious browser extension to hijack the AI assistant/agent features built into several Chromium-based browsers and AI browsing tools, including Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The core technique, described as "Prompt Forcing," reportedly earned the researcher over $20,000 in bug bounties and resulted in two CVEs being assigned, though this report does not specify which CVEs or which vendors issued them.

Why it matters for defenders

AI browser agents are increasingly granted the ability to read page content, click through workflows, and take actions on a user's behalf inside the browser. If a single malicious or compromised extension can influence or redirect what that agent does, the attack surface extends well beyond traditional extension abuse (credential theft, ad injection) into a request that the AI agent itself perform harmful actions with the user's existing session and permissions. Because the technique reportedly affects multiple browsers and AI assistants rather than one isolated product, organizations that have started rolling out AI-assisted browsing tools should treat this as a class of risk to evaluate, not a single-vendor bug.

What defenders should watch for or do now

  • Inventory and restrict which browser extensions are permitted in your environment, especially on machines where AI browser agents or assistants are enabled.
  • Review vendor security advisories for the browsers and AI-assistant products named above for patches tied to this disclosure, since specific CVE identifiers were not included in this initial report.
  • Where possible, monitor for anomalous AI-agent behavior — actions taken by an in-browser assistant that deviate from the user's explicit prompt or that occur immediately after a new/updated extension is installed.
  • Apply the principle of least privilege to AI browser agent permissions (e.g., limit autonomous form-filling, purchasing, or credential access) until the scope of Prompt Forcing-style manipulation is better understood.

Developing story

Details here are based on a single news report and researcher disclosure; the underlying CVEs, affected versions, and vendor remediation status are not yet fully specified. This is net-new intelligence and df00tech will track it for updates. Read the original coverage at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.