express gazette logo
The Express Gazette
Monday, September 28, 2026

Malicious Browser Extensions Could Hijack AI Assistants, Researcher Finds

A security researcher demonstrated how malicious browser extensions could exploit AI assistants integrated into browsers, potentially leading to unauthorized access to sensitive information and system control.

US Politics • 2 hours ago
Malicious Browser Extensions Could Hijack AI Assistants, Researcher Finds

A security researcher has demonstrated how malicious browser extensions could exploit the capabilities of AI assistants integrated into web browsers, potentially turning these tools against users. The research, dubbed BragJack by its discoverer Gal Weizman of Forever Security, targeted AI assistants like Gemini in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon, and Anthropic's Claude within Chrome.

The attack, which earned over $20,000 in bug bounties and two CVEs, requires the malicious extension to be installed first. However, once installed, Weizman showed that these extensions could execute attacks with zero additional clicks from the victim. The vulnerability stems from the way these AI assistants are designed, granting them deep access to browser functions.

How Extensions Can Access Browser AI

Weizman explained that these AI systems function with an "AI model" and a "privileged component." The AI model processes requests, while the browser component executes them, potentially reading webpage content, capturing screenshots, or interacting with websites. A malicious extension can exploit this setup by manipulating the connection between these two parts, particularly through Chromium's declarativeNetRequest (DNR) system, which extensions can use to modify network requests.

Chrome's Gemini Vulnerability Exposed Files and Screenshots

In Chrome, the Gemini side panel's AI and browser-level abilities were found to be susceptible. Although extensions were prevented from directly injecting scripts into the Gemini page, researchers found a gap that allowed manipulation of certain network requests. This enabled Weizman to access local files, capture screenshots, and obtain browser profile information. He also demonstrated the ability to activate the camera and microphone without user interaction. Google has since confirmed it released a patch in Chrome to address this specific vulnerability (CVE-2026-0628).

Perplexity Comet Attack Could Compromise Emails

Perplexity Comet, an AI agent capable of taking actions within websites, presented a different risk. Weizman discovered that a testing domain used by Perplexity lacked the same extension protections as the main site. By using DNR to bypass a redirect, the malicious extension could interact with Comet's agent, gaining access to browsing history, screenshots, and local files. The researcher demonstrated an attack where the agent was instructed to summarize a victim's recent emails and send them to another address.

Microsoft Edge Race Condition Bypassed Safeguards

Microsoft Edge had safeguards against external prompts controlling its AI agent, but researchers found a timing flaw, or race condition. A malicious extension could submit a prompt and then quickly activate the AI's action capabilities before Edge could fully verify the request. This allowed the AI agent to execute commands it should have rejected. Microsoft has addressed this flaw, tracked as CVE-2026-55945, in versions after 150.0.4078.48.

Opera Neon and Claude Also Vulnerable

Related attacks were also demonstrated against Opera Neon and Claude in Chrome. Claude, being a browser extension itself, could be manipulated by another extension through a trusted page on its domain. Anthropic awarded a bounty for this finding. Opera Neon also allowed a proof-of-concept extension to reach its AI agent and force it to perform website actions. All demonstrated attacks were based on the Chromium framework, allowing for a similar attack methodology across different browsers.

Person typing on their computer.

Prompt Forcing: A New Attack Vector

This new attack method, termed "Prompt Forcing" by Weizman, differs from prompt injection. Instead of hiding malicious instructions within content an AI reads, Prompt Forcing allows an attacker to directly insert a command into the AI agent through a trusted channel. This makes malicious actions appear as normal browser activity, posing a challenge for security software. The BragJack research details proof-of-concept attacks and does not report widespread exploitation, but it highlights evolving security risks as AI gains deeper browser access.

Protecting Against Malicious Extensions

Experts advise users to take proactive steps to secure their browsers:

  • Keep Browsers Updated: Regularly install browser updates to receive critical security fixes.
  • Remove Unused Extensions: Uninstall any browser extensions that are no longer needed or recognized.
  • Check Permissions: Carefully review the permissions requested by extensions before installation, ensuring they align with the extension's functionality.
  • Limit Extension Access: When possible, restrict extensions to run only on specific websites rather than all sites.
  • Exercise Caution with AI Extensions: Verify the publisher of extensions, especially those claiming AI capabilities, to ensure they are legitimate.
  • Disable Unused AI Features: Turn off AI browser features that are not actively used.
  • Use Antivirus Software: Employ robust antivirus software to detect malicious downloads and suspicious activity.
  • Treat Extensions as Applications: Install extensions with the same caution as any application, considering the code and permissions they add to the browser.

Sources