ALEXKRI.NET
Resume Contact
← Back

BragJack attacks hijack AI browser agents through malicious extensions

We spent years deciding browser extensions were a manageable risk. Then we handed the browser an AI agent with privileged access, and the maths changed. BragJack abuses declarativeNetRequest — a permission plenty of legitimate extensions hold — to weaken security headers and inject into the assistant’s context, hitting Gemini Live, Comet, Edge, Opera Neon and Claude in Chrome. Google and Microsoft patched (CVE-2026-0628, CVE-2026-55945).

Read the source ↗