What matters in AI.

Subscribe

Learn / AI agents

Definition · AI agents

Prompt Forcing

Prompt Forcing is an attack in which a lower-trust component, such as a browser extension or a website, makes an AI agent accept prompts as if the user had sent them. An attacker who can keep sending prompts can also answer when the agent hesitates. Gal Weizman of Forever Security introduced the term publicly in September 2026.

Last reviewed

Key points

  • Prompt Forcing hands an AI agent a whole prompt through the channel the agent trusts to speak for the user. Nothing is hidden in content the agent reads.
  • If the attacker can keep sending prompts, they can answer when the agent hesitates or asks for confirmation. Weizman says that was often needed to finish his attacks.
  • Weizman argues that models keep getting better at spotting injected instructions, but that a model is far less likely to become suspicious of prompts it believes the user sent.
  • The term is new. Gal Weizman of Forever Security introduced it publicly in September 2026, and both instances he lists, BragJack and MaXSS, are his own research.

How it works

An AI agent takes prompts from a place it trusts to speak for the user: a chat box, a browser side panel, a message channel from the vendor’s own page. Prompt Forcing happens when something with less trust can write into that place. Weizman calls it a “lower-trust component”. The agent treats the attacker’s prompt as the user’s request, and whatever it does looks as if the user started it. It may still hesitate over a malicious request, as the agents in Weizman’s research sometimes did.

Weizman separates Prompt Forcing from prompt injection on two points:

  • Nothing is polluted. In direct prompt injection, attacker text is added to a legitimate prompt. In indirect prompt injection, it is planted in data the agent reads. In Prompt Forcing the attacker feeds the agent the whole prompt.
  • The attacker stays in the conversation. An injected instruction usually gets one chance. If the agent asks for approval, the attacker cannot answer. A forced prompt can be followed by another one.

Why it matters

Weizman calls prompt injection “a statistical attack”: the better models get, the better they tell injected instructions apart from data. A forced prompt arrives as the user’s own, and in his words “the model is far less likely to become suspicious of prompts it believes the user provided”.

Being able to reply also mattered in his research. The agents sometimes asked Weizman whether he was sure, and answering was “often necessary to complete the attack.”

CyberSecurityNews, reporting on BragJack, goes further than Weizman: it says that attack “abuses authorization and message-channel trust before the AI evaluates intent, so model-level safety filters cannot correct the isolation failure”. In Weizman’s research, though, the agents did sometimes hesitate. Forever Security’s own answer, in the BragJack write-up, is “an AI-native endpoint solution”, which is what it sells.

In practice

Weizman lists two instances, both from Forever Security:

  • BragJack (September 2026). An ordinary browser extension sent its own prompts to the AI agents in Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Its Chrome attack did not hijack the agent.
  • MaXSS (June 2026). A flaw in the MaxAI Chrome extension, installed on over 1,000,000 devices according to the Chrome and Edge stores, let any website run code on any other site in the victim’s browser. The write-up lists forcing prompts on Claude, Gemini or ChatGPT among the impacts, and says it “is also easy to do”. It does not show that step.

Questions and answers

What is Prompt Forcing?

Prompt Forcing is an attack, named by Gal Weizman of Forever Security in September 2026, in which a lower-trust component such as a browser extension makes an AI agent accept prompts as if the user had sent them. The attacker writes the whole prompt and, if they can keep sending prompts, can answer when the agent hesitates.

Is Prompt Forcing a kind of prompt injection?

Gal Weizman, who named it, says no. In direct prompt injection the attacker adds instructions to a legitimate prompt; in indirect prompt injection they plant them in data the agent reads. In Prompt Forcing the attacker writes the entire prompt through the channel the agent trusts, and can keep the conversation going.

Is Prompt Forcing a widely used term?

Not yet. Weizman introduced it in September 2026, and the news reports that repeat it attribute it to him. The two instances he lists, BragJack and MaXSS, are both Forever Security research.

Sources

  1. Prompt Forcing: The Scarier Sibling of Prompt InjectionForever Security, 24 Sep 2026
  2. BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI AssistantsForever Security, 16 Sep 2026
  3. MaXSS: Chrome Extension MaxAI Vulnerable to UXSS Puts 1,000,000 Users at RiskForever Security, 10 Jun 2026
  4. BragJack attacks hijack AI browser agents through malicious extensionsBleepingComputer, 19 Sep 2026
  5. BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major BrowsersCyber Security News, 19 Sep 2026

Guides that use this term