CVE Tools

BragJack Attack Can Turn a Browser's Agentic AI Against It

Dark ReadingBy Elizabeth Montalbano

PoC publicChromeEdge

Our summary

Researchers released the BragJack proof of concept, showing how malicious browser extensions could seize control of built-in AI agents in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. The flaws, including CVE-2026-0628 in Chrome and CVE-2026-55945 in Edge, could enable access to sensitive data and actions on authenticated websites; the affected vendors have addressed the reported issues.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store