Researcher Shows 1 Extension Can Hijack 5 AI Browser Assistants, Triggering 2 CVEs
Updated
Updated · Fox News · Sep 28
Researcher Shows 1 Extension Can Hijack 5 AI Browser Assistants, Triggering 2 CVEs
2 articles · Updated · Fox News · Sep 28
Summary
Gal Weizman of Forever Security showed that a malicious browser extension could hijack AI assistants in Chrome, Edge, Perplexity Comet, Opera Neon and Claude in Chrome after installation, then act with zero further clicks.
The BragJack proof of concept abused trusted links between AI models and privileged browser components—largely through Chromium's declarativeNetRequest system—to force prompts and gain access normal extensions should not have.
Chrome's Gemini side panel was shown exposing local files, screenshots, profile data, camera and microphone access; Google assigned CVE-2026-0628, paid a $7,000 bounty and said it patched the attack path.
Perplexity Comet was demonstrated reading history, screenshots and local files, then using its web-action agent to summarize recent emails and send them elsewhere; Microsoft separately fixed an Edge race-condition flaw tracked as CVE-2026-55945.
The research earned more than $20,000 in bug bounties and reported no known in-the-wild abuse, but it highlights how browser AI agents expand the damage a single malicious extension can do.