BragJack is the name Forever Security gave to a family of techniques that allow a browser extension to cross the boundary between websites and privileged AI components. Published on September 16, 2026, the research shows that the same core idea could affect Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome. These were controlled demonstrations, with no public evidence of exploitation in the wild.

The “Brain” and “Body” of an AI Assistant
Browsers with integrated AI commonly split the system into two parts. The “brain” runs on the provider's servers to interpret requests and generate instructions; the “body” resides in the browser and can read content, take screenshots, open files, or perform actions. Because the latter holds powerful privileges, it should accept commands only from a trusted domain or page.
Ordinary extensions may modify pages through content scripts and adjust some traffic through the API declarativeNetRequest. BragJack uses these common permissions to inject code or alter network responses from a page trusted by the AI. Once that trust boundary is broken, attacker commands can reach the AI component as though they came from the provider.
How Is BragJack Different from Prompt Injection?
Prompt injection usually embeds a malicious instruction in data the model reads. In this research, the extension could create the entire request, choose when to send it, and continue with chained follow-up requests. Forever Security calls this approach “prompt forcing.” The main risk is not merely an incorrect model response, but an untrusted channel gaining control of a privileged tool.
Five Products, Different Forms of Impact
On Chrome, the earlier technique named GlicJack could read local files, take screenshots, and activate the camera and microphone. The flaw is tracked as CVE-2026-0628 and was fixed by Google in Chrome 143.0.7499.192.
For Edge, the researcher combined the privileges of a Microsoft marketing page with a race condition between “Think” and “Do” modes. The chain was assigned CVE-2026-55945 and Microsoft fixed it in Edge 150.0.4078.48.
Opera Neon and Claude in Chrome allowed an extension to reach a page authorized to send commands to the AI assistant. The Claude case was considered less severe because one extension affected another extension rather than taking over a privileged browser component.
The research assessed Perplexity Comet as having the broadest impact. A leftover testing domain remained trusted by the assistant without the protections applied to the primary domain. By blocking a redirect and injecting code into that domain, the test extension could ask the agent to read files, view browsing history, take screenshots, and act as the user.
Why Is the Risk Significant?
An AI agent can accomplish a goal through legitimate actions of trusted software instead of running a fixed malicious payload. This makes detection based only on malware signatures less effective. Damage also depends on the privileges developers grant the agent: the broader the access, the greater the consequences of a trust-boundary failure.
However, all BragJack scenarios assume that a malicious extension is already installed and running on the device. At publication time, neither CVE appeared in CISA's Known Exploited Vulnerabilities catalog. The findings should therefore be understood as a warning about design and privilege management, not evidence of an active attack campaign.
Recommendations for Users and Organizations
- Update Chrome to 143.0.7499.192 and Edge to 150.0.4078.48 or later.
- Keep Comet, Opera Neon, and Claude in Chrome updated and review each vendor's security advisories.
- Remove extensions that are no longer needed and carefully review permissions to read or change website data and modify network traffic.
- In enterprise environments, enforce an extension allowlist, prevent unrestricted installation, and monitor permission changes after updates.
- Limit the data, accounts, and tools accessible to AI agents, and separate sensitive sessions from ordinary browser profiles.
Secure-Design Lessons for AI Browsers
BragJack shows that a trusted web domain should not automatically become an identity authorized to control an agent. Developers need layered message authentication, isolation of privileged interfaces from content scripts and traffic-modification APIs, removal of testing domains, and explicit confirmation for sensitive actions. Agent permissions should also follow least privilege and be logged in enough detail for investigation.
As browsers evolve from display tools into agents that can act, their threat models must evolve as well. Protecting prompts is necessary but insufficient; the boundaries among extensions, trusted web pages, AI services, and privileged APIs require the strongest controls.
VNCyberS compiled from Forever Security and The Hacker News















