Definition · AI agents
BragJack
BragJack is an attack in which a malicious browser extension gets its code onto a web page that a browser's AI agent trusts to send it instructions, then uses that page to send the agent commands or whole prompts of its own. Forever Security published BragJack in September 2026 against five Chromium-based browser agents.
Last reviewed
Key points
- BragJack is an attack in which a malicious browser extension gets its code onto a page that an AI agent in the browser trusts for instructions. From there it sends the agent commands, or writes its prompts outright, instead of hiding instructions in content the agent reads.
- Gal Weizman of Forever Security published it on 16 September 2026 against five browser agents. Its Chrome part was published earlier that year as GlicJack. Four agents were hijacked; the Chrome flaw exposed files, screenshots, camera and microphone instead.
- Weizman calls the technique Prompt Forcing. The attacker sends the entire prompt and can send another when the agent hesitates, so no single injected instruction has to succeed on its own.
- The victim must already have the extension installed; after that, Forever Security reports zero clicks. The work produced two CVEs and roughly $20,000 in bounties.
- The flaw is not in the model. Each agent trusted a page that an extension could get code onto.
How it works
Each browser agent has a body and a brain, in Weizman’s terms. The body is a privileged component that can open tabs, take screenshots or read files. The brain is the vendor’s web app, which passes the AI model’s instructions to the body. The body obeys the pages it trusts.
BragJack gets the extension’s own code onto one of those trusted pages. Opera
left opera.com open to extension scripts. Chrome blocked extension scripts on
its Gemini page, so Weizman used declarativeNetRequest, a permission that
rewrites network traffic, to strip security headers and swap in his own
script. Perplexity’s agent also trusted a testing domain; the extension
removed its redirect and ran a script there. On Edge and
Claude in Chrome, the weak page was a marketing page allowed to send prompts.
On Chrome, the extension sent the body commands directly, skipping the Gemini model. On the other four, it sent a whole prompt, such as one to email a summary of the user’s inbox to the attacker, and the agent treated it as if the user had typed it. Weizman calls this Prompt Forcing: “a lower-trust component makes an agent accept prompts as if they came from the user.”
Why it matters
In prompt injection, Weizman writes, the attacker usually gets one chance and cannot reply if the agent hesitates. With Prompt Forcing, when an agent asked whether he was sure, Weizman sent another prompt; he says that was often needed to finish the attack.
Forever Security reports zero clicks once the extension is installed. Weizman argues a traditional EDR “would never catch this”, because no malicious code performs the final action. A trusted agent does, with privileges it already holds.
In practice
Four of the five agents were hijacked outright: Perplexity Comet, Microsoft Edge, Opera Neon and Claude in Chrome. Chrome’s Gemini agent could only read at the time, so that flaw gave the extension local files, screenshots, and the picture and email address of the signed-in profile instead. The attacked pane also had automatic camera and microphone permission. Google fixed it in Chrome 143.0.7499.192 as CVE-2026-0628. Weizman had first published the Chrome finding earlier in 2026 as GlicJack.
Microsoft had tried hard to block the technique. It split the Edge agent
so that a prompt sent from the marketing page could not also trigger actions. Weizman switched
actions off, sent the prompt, and switched them back on before the agent
checked. Microsoft assigned that race condition CVE-2026-55945. On Edge and
Claude in Chrome, the extension also needed the debugger permission, to fake
the user click those pages required.
Forever Security lists bounties of $7,000 each from Google and Perplexity, $5,000 from Microsoft, $900 from Opera, and $600 from Anthropic ($500 in the technical write-up). Anthropic rated the Claude in Chrome finding medium severity. Weizman calls that case “the most unfair matchup”, because it was one extension attacking another rather than an extension breaking into the browser.
Questions and answers
What is BragJack?
BragJack is an attack published by Gal Weizman of Forever Security in September 2026. A malicious browser extension gets its code onto a web page that a browser's AI agent trusts for instructions, then sends the agent commands or whole prompts directly. It was shown against Gemini in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension.
Is BragJack prompt injection?
Its discoverer says no. Prompt injection adds attacker instructions to a prompt or to the data an agent processes, and the model has to be fooled into following them. In BragJack the extension writes the whole prompt through the channel the agent treats as the user, and can keep sending follow-ups. Weizman calls this Prompt Forcing.
Does BragJack need the user to do anything?
The victim has to have the malicious extension installed. After that, Forever Security reports zero clicks were required against all five targets. On Edge and Claude in Chrome, the extension used the debugger permission to fake the user click those agents expected.
Has BragJack been fixed?
Google fixed the Chrome flaw, CVE-2026-0628, in Chrome 143.0.7499.192. BleepingComputer reports that Microsoft has resolved the Edge race condition, CVE-2026-55945. The sources give no fix status for Comet, Opera Neon or Claude in Chrome. BleepingComputer advises keeping browsers updated, removing unrecognised extensions, and being wary of any extension that asks to "read and change all your data on all websites".
Sources
- BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI AssistantsForever Security, 16 Sep 2026
- BragJack [Technical Overview]: How We Hijacked Top 5 Browsers' Internal Agents With Just One Single ExtensionForever Security, 16 Sep 2026
- Prompt Forcing: The Scarier Sibling of Prompt InjectionForever Security, 24 Sep 2026
- BragJack attacks hijack AI browser agents through malicious extensionsBleepingComputer, 19 Sep 2026
- CVE-2026-0628 DetailNIST National Vulnerability Database, 7 Jan 2026
- CVE-2026-55945 DetailNIST National Vulnerability Database, 3 Jul 2026