Proof‑of‑Concept ‘BragJack’ Uses Browser Extensions to Seize AI Assistants
Researchers have unveiled a proof‑of‑concept exploit called BragJack, showing that one rogue browser extension is capable of commandeering multiple AI chat assistants built into common web browsers.
Created by security analyst Gal Weizman of Forever Security, the method attacks extensions on Chrome, Edge, Opera Neon, the Perplexity Comet service, and the Claude model when accessed via Chrome, inserting harmful prompts that steer the AI’s responses.
The BragJack exploit uses a prompt‑forcing technique that gently alters the commands an AI agent is given, prompting it to perform unintended tasks or reveal data it would otherwise safeguard. Deploying the identical extension on various platforms illustrates how a modest snippet of code can jeopardize a broad spectrum of AI‑powered functionalities.
The finding netted over $20,000 in bug‑bounty rewards and led to the assignment of two distinct CVE numbers, highlighting the seriousness of the fundamental vulnerability in the extension permission framework.
Browsers are progressively embedding AI assistants to deliver real‑time help, such as composing emails or responding to questions. This integration widens the attack surface, since extensions—frequently given extensive rights—can act as a pathway for malicious prompt injection.
Browser makers have started examining the results and are anticipated to roll out updates that reinforce extension sandboxing and curb third‑party code from tampering with AI prompt streams. Security professionals recommend that users install extensions solely from reputable sources and keep a close eye on updates as the ecosystem responds to this new danger.
Comments (0)
Be the first to comment.
Join the discussion