{"id":2029,"date":"2026-09-17T07:20:23","date_gmt":"2026-09-17T00:20:23","guid":{"rendered":"https:\/\/vncybers.vn\/hieu-ve-bragjack-extension-chiem-quyen-tro-ly-ai-trinh-duyet\/"},"modified":"2026-09-17T07:20:23","modified_gmt":"2026-09-17T00:20:23","slug":"understanding-bragjack-how-one-extension-can-hijack-browser-ai-assistants-2","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/hieu-ve-bragjack-extension-chiem-quyen-tro-ly-ai-trinh-duyet\/","title":{"rendered":"Understanding BragJack: Why an extension can hijack an AI assistant in the browser"},"content":{"rendered":"<p><strong>BragJack<\/strong> is the name Forever Security gave to a family of techniques that allow a browser extension to cross the boundary between websites and privileged AI components. Published on September 16, 2026, the research shows that the same core idea could affect Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome. These were controlled demonstrations, with no public evidence of exploitation in the wild.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/09\/bragjack-inline.webp\" alt=\"Minh h\u1ecda nghi\u00ean c\u1ee9u BragJack v\u1ec1 tr\u1ee3 l\u00fd AI trong tr\u00ecnh duy\u1ec7t\"\/><figcaption class=\"wp-element-caption\">The BragJack research describes how an extension could reach privileged AI assistants. Image: The Hacker News<\/figcaption><\/figure>\n<h2>The \u201cBrain\u201d and \u201cBody\u201d of an AI Assistant<\/h2>\n<p>Browsers with integrated AI commonly split the system into two parts. The \u201cbrain\u201d runs on the provider's servers to interpret requests and generate instructions; the \u201cbody\u201d resides in the browser and can read content, take screenshots, open files, or perform actions. Because the latter holds powerful privileges, it should accept commands only from a trusted domain or page.<\/p>\n<p>Ordinary extensions may modify pages through content scripts and adjust some traffic through the API <code>declarativeNetRequest<\/code>. BragJack uses these common permissions to inject code or alter network responses from a page trusted by the AI. Once that trust boundary is broken, attacker commands can reach the AI component as though they came from the provider.<\/p>\n<h2>How Is BragJack Different from Prompt Injection?<\/h2>\n<p>Prompt injection usually embeds a malicious instruction in data the model reads. In this research, the extension could create the entire request, choose when to send it, and continue with chained follow-up requests. Forever Security calls this approach \u201cprompt forcing.\u201d The main risk is not merely an incorrect model response, but an untrusted channel gaining control of a privileged tool.<\/p>\n<h2>Five Products, Different Forms of Impact<\/h2>\n<p>On Chrome, the earlier technique named GlicJack could read local files, take screenshots, and activate the camera and microphone. The flaw is tracked as <strong>CVE-2026-0628<\/strong> and was fixed by Google in Chrome 143.0.7499.192.<\/p>\n<p>For Edge, the researcher combined the privileges of a Microsoft marketing page with a race condition between \u201cThink\u201d and \u201cDo\u201d modes. The chain was assigned <strong>CVE-2026-55945<\/strong> and Microsoft fixed it in Edge 150.0.4078.48.<\/p>\n<p>Opera Neon and Claude in Chrome allowed an extension to reach a page authorized to send commands to the AI assistant. The Claude case was considered less severe because one extension affected another extension rather than taking over a privileged browser component.<\/p>\n<p>The research assessed Perplexity Comet as having the broadest impact. A leftover testing domain remained trusted by the assistant without the protections applied to the primary domain. By blocking a redirect and injecting code into that domain, the test extension could ask the agent to read files, view browsing history, take screenshots, and act as the user.<\/p>\n<h2>Why Is the Risk Significant?<\/h2>\n<p>An AI agent can accomplish a goal through legitimate actions of trusted software instead of running a fixed malicious payload. This makes detection based only on malware signatures less effective. Damage also depends on the privileges developers grant the agent: the broader the access, the greater the consequences of a trust-boundary failure.<\/p>\n<p>However, all BragJack scenarios assume that a malicious extension is already installed and running on the device. At publication time, neither CVE appeared in CISA's Known Exploited Vulnerabilities catalog. The findings should therefore be understood as a warning about design and privilege management, not evidence of an active attack campaign.<\/p>\n<h2>Recommendations for Users and Organizations<\/h2>\n<ul>\n<li>Update Chrome to 143.0.7499.192 and Edge to 150.0.4078.48 or later.<\/li>\n<li>Keep Comet, Opera Neon, and Claude in Chrome updated and review each vendor's security advisories.<\/li>\n<li>Remove extensions that are no longer needed and carefully review permissions to read or change website data and modify network traffic.<\/li>\n<li>In enterprise environments, enforce an extension allowlist, prevent unrestricted installation, and monitor permission changes after updates.<\/li>\n<li>Limit the data, accounts, and tools accessible to AI agents, and separate sensitive sessions from ordinary browser profiles.<\/li>\n<\/ul>\n<h2>Secure-Design Lessons for AI Browsers<\/h2>\n<p>BragJack shows that a trusted web domain should not automatically become an identity authorized to control an agent. Developers need layered message authentication, isolation of privileged interfaces from content scripts and traffic-modification APIs, removal of testing domains, and explicit confirmation for sensitive actions. Agent permissions should also follow least privilege and be logged in enough detail for investigation.<\/p>\n<p>As browsers evolve from display tools into agents that can act, their threat models must evolve as well. Protecting prompts is necessary but insufficient; the boundaries among extensions, trusted web pages, AI services, and privileged APIs require the strongest controls.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from Forever Security and The Hacker News<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>BragJack l\u00e0 t\u00ean nh\u00f3m nghi\u00ean c\u1ee9u Forever Security \u0111\u1eb7t cho m\u1ed9t chu\u1ed7i k\u1ef9 thu\u1eadt cho ph\u00e9p extension tr\u00ecnh duy\u1ec7t v\u01b0\u1ee3t qua ranh gi\u1edbi v\u1ed1n c\u00f3 gi\u1eefa trang web v\u00e0 th\u00e0nh ph\u1ea7n AI \u0111\u1eb7c quy\u1ec1n. Nghi\u00ean c\u1ee9u c\u00f4ng b\u1ed1 ng\u00e0y 16\/9\/2026 cho th\u1ea5y c\u00f9ng m\u1ed9t \u00fd t\u01b0\u1edfng c\u00f3 th\u1ec3 t\u00e1c \u0111\u1ed9ng \u0111\u1ebfn Gemini Live trong Chrome, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":2028,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[308,821,445,825,826,823,828,827,824,822],"class_list":["post-2029","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-kien-thuc","tag-ai-agent","tag-bragjack","tag-browser-security","tag-cve-2026-0628","tag-cve-2026-55945","tag-extension-trinh-duyet","tag-gemini-live","tag-perplexity-comet","tag-prompt-forcing","tag-tro-ly-ai"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2029","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=2029"}],"version-history":[{"count":0,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2029\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/2028"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=2029"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=2029"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=2029"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}