Forever Security disclosed BragJack, a proof-of-concept attack in which a malicious browser extension can abuse trusted communication paths between webpages and browser-based AI assistants to issue commands appearing to originate from a vendor-authorized source. The technique affected Gemini Live in Chrome, Microsoft Edge Copilot, Opera Neon, Perplexity Comet, and Claude in Chrome; potential impact ranged from AI-agent control to access to local files, browser-profile data, browsing history, screenshots, and—in Chrome—camera and microphone access.
Exploitation requires a victim to install and run the malicious extension, which can use webpage-modification capabilities and declarativeNetRequest rules to manipulate trusted origins, resources, or message channels. Google fixed the Chrome Gemini flaw, tracked as CVE-2026-0628 (CVSS 8.8), in Chrome 143.0.7499.192/.193, while Microsoft fixed the Edge Copilot race condition, CVE-2026-55945, in Edge 150.0.4078.48. Researchers reported no evidence of in-the-wild exploitation; organizations should patch affected browsers, allowlist extensions, restrict broad host, DNR, and debugger permissions, and monitor sensitive AI-agent activity.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft fixed the Edge Copilot race-condition issue tracked as CVE-2026-55945 in Edge version 150.0.4078.48. The issue could enable forced prompts by timing a switch between Copilot's Think and Do modes.
The affected vendors awarded Forever Security approximately $20,000 in combined bug bounties for the reported findings, including rewards from Google, Perplexity, Microsoft, Opera, and Anthropic. Anthropic rated the Claude in Chrome finding as medium severity and said it was the first report of that issue.
Google fixed the high-severity Chrome Gemini issue CVE-2026-0628, also described as GlicJack, in Chrome 143.0.7499.192 and .193. The flaw allowed declarativeNetRequest rules to replace a resource in Gemini's trusted WebView context after a malicious extension was installed.
Forever Security researcher Gal Weizman demonstrated that a malicious installed extension could abuse trusted browser-to-AI communication paths to control AI assistants in Chrome Gemini, Perplexity Comet, Edge Copilot, Opera Neon, and Claude in Chrome. The demonstrations showed potential access to sensitive capabilities including local files, screenshots, browser data, and—in Chrome—camera and microphone access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.