Skip to main content
CyberSingle-sourceMedium
5.1

BragJack PoC hijacks AI browser agents via malicious extensions

Security researcher Gal Weizman demonstrated BragJack, a proof-of-concept attack that uses a single malicious browser extension to hijack AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs, highlighting a systemic vulnerability in AI-integrated browsers. The attack's practical exploitation in the wild remains unconfirmed, but the broad impact across major browsers elevates its significance for AI security.

BleepingComputer4 days agoengCredibility 27%View source

Score Breakdown

Mosaic Score5.1
Confidence0.7
Significance0.5
Source credibility0.3
Source

Related signals

3 found