Select a theme from the list.
Insights

From our experts

Latest
CaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsDeparted Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackBragJack Turns Malicious Browser Extensions Into AI Agent ControllersWindows 11 Tests Remote Cloud Rebuild for Faster Enterprise RecoveryPublic Linux Root Exploits Put Unpatched Servers on a Short ClockGyazo Breach Turns Screenshot Metadata Into a Privacy CrisisMicrosoft's Email Benchmark Shows Why Inbox Defense Cannot Stop at DeliveryMalicious DNS Zones Can Turn Unbound Resolvers Into Code-Execution TargetsRatHat Gives Android Malware an AI-Powered Pair of HandsMITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model ChangeParaShells Flaw Leaves Intel Mac Users Without a Confirmed Parallels FixWindows 11 Security Update Knocks Some Enterprise PCs Off Their DomainsCaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsDeparted Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackBragJack Turns Malicious Browser Extensions Into AI Agent ControllersWindows 11 Tests Remote Cloud Rebuild for Faster Enterprise RecoveryPublic Linux Root Exploits Put Unpatched Servers on a Short ClockGyazo Breach Turns Screenshot Metadata Into a Privacy CrisisMicrosoft's Email Benchmark Shows Why Inbox Defense Cannot Stop at DeliveryMalicious DNS Zones Can Turn Unbound Resolvers Into Code-Execution TargetsRatHat Gives Android Malware an AI-Powered Pair of HandsMITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model ChangeParaShells Flaw Leaves Intel Mac Users Without a Confirmed Parallels FixWindows 11 Security Update Knocks Some Enterprise PCs Off Their Domains
Security Insight

BragJack Turns Malicious Browser Extensions Into AI Agent Controllers

BragJack Turns Malicious Browser Extensions Into AI Agent Controllers
Photo by Pavel Danilyuk on Pexels

A proof-of-concept technique called BragJack demonstrates how a malicious Chromium extension can seize control of privileged browser AI assistants. The research affected assistants associated with Chrome, Edge, Perplexity, Opera and Anthropic, showing that browser extensions can become a bridge between ordinary web access and powerful agentic actions. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/amp/))

Browser extensions have long presented a security tradeoff: they add useful capabilities, but frequently receive permission to inspect pages, alter traffic and access browsing data. The BragJack research shows that this familiar risk becomes considerably more serious when a browser also contains an AI assistant capable of reading files, taking screenshots or acting on websites.

Security researcher Gal Weizman demonstrated the technique against five Chromium-based browsers or assistants, including Google Chrome's Gemini Live, Microsoft Edge, Perplexity Comet, Opera Neon and Claude in Chrome. The proof-of-concept required a malicious extension to be installed, but subsequent agent manipulation could occur without further interaction from the user. Google and Microsoft have resolved the assigned vulnerabilities. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/amp/))

Why Browser AI Changes the Risk

BragJack exploited the gap between an AI model that decides what to do and a privileged browser component that carries out the action. Chromium's declarativeNetRequest capability allowed the extension to alter headers, redirect resources or manipulate content trusted by the assistant.

Against agentic browsers, the consequences went beyond data visibility. The researcher demonstrated access to browser history, screenshots and local files, as well as the ability to issue instructions to an agent. In one example, an assistant was directed to summarize email content and send the result elsewhere. A separate race condition affected the division between thinking and action modes in Edge.

Defensive Priorities

  • Remove browser extensions that are unnecessary, abandoned or unfamiliar.
  • Restrict extensions requesting access to data on every website.
  • Use enterprise browser policies to maintain approved extension lists.
  • Keep browsers and integrated AI components fully updated.
  • Monitor extension installations and permission changes as security events.

In my view, BragJack reveals that extension governance can no longer be treated as a minor browser-management task. As AI assistants gain authority to act for users, the browser becomes an execution environment for delegated decisions. Organizations should therefore apply least privilege not only to human accounts, but also to extensions, assistants and the communication paths connecting them.

Talk to our team →

Latest

CaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsSep 20, 2026Departed Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackSep 20, 2026BragJack Turns Malicious Browser Extensions Into AI Agent ControllersSep 20, 2026Windows 11 Tests Remote Cloud Rebuild for Faster Enterprise RecoverySep 19, 2026Public Linux Root Exploits Put Unpatched Servers on a Short ClockSep 19, 2026Gyazo Breach Turns Screenshot Metadata Into a Privacy CrisisSep 19, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning3Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points4IDScan Lawsuits Put Mass Identity Collection Under the Microscope5Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server Memory6BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session Hijacking