CVE Tools

BragJack attacks hijack AI browser agents through malicious extensions

BleepingComputerBy Ax Sharma

PoC publicGoogle ChromePerplexity Comet

Our summary

Researcher Gal Weizman demonstrated BragJack, a proof-of-concept technique in which an already-installed malicious extension can take over AI browser assistants in Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome. The flaws can enable access to sensitive browser data and cause agents to perform actions for victims; Google fixed CVE-2026-0628 and Microsoft fixed CVE-2026-55945. Users should update their browsers and review extensions with broad site-data permissions.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store