Researcher Gal Weizman of Forever Security disclosed BragJack, a proof-of-concept attack in which a malicious Chromium extension uses prompt forcing to seize control of built-in AI assistants. The technique affects Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude for Chrome extension; it requires a victim to first install an extension granted ordinary page-modification and declarativeNetRequest permissions. No confirmed in-the-wild exploitation has been reported.
Once an AI agent is compromised, it could read local files and web content, capture screenshots, and perform actions as the logged-in user, including processing and sending email content. Google addressed the Chrome component as high-severity CVE-2026-0628 (CVSS 8.8), an insufficient-policy-enforcement flaw in the WebView tag reported by Weizman, in Chrome 143.0.7499.192/.193; Microsoft fixed the related Edge issue, CVE-2026-55945, in Edge 150.0.4078.48. Organizations should ensure managed browsers are updated and restrict extension installation to approved sources.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Gal Weizman reported CVE-2026-0628, a high-severity insufficient-policy-enforcement vulnerability involving Chrome's WebView tag, to Google.
Microsoft assigned CVE-2026-55945 to an Edge race condition that could enable prompt delivery while switching between Think and Do modes, and fixed it in Edge 150.0.4078.48.
Forever Security researcher Gal Weizman demonstrated BragJack, or Prompt Forcing, a proof-of-concept technique in which a malicious browser extension can directly supply controlling prompts to built-in browser AI assistants. The technique was demonstrated against Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude for Chrome; no real-world attacks were observed.
Google released Chrome Stable 143.0.7499.192/.193 for Windows and macOS and 143.0.7499.192 for Linux, including a fix for CVE-2026-0628.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourceforever.security
Open sourcechromereleases.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.