Key takeaways
- Security researcher Gal Weizman of Forever Security disclosed “BragJack,” showing that an ordinary browser extension can hijack internal AI agents across five Chromium environments.
- The attack weaponizes “Prompt Forcing” and Chromium declarativeNetRequest (DNR) rules to bypass model guardrails and communicate directly with privileged browser components.
- Once installed, the malicious extension requires zero user interaction to read local files, capture screenshots, access browsing histories, or exfiltrate private emails.
- Google (CVE-2026-0628) and Microsoft (CVE-2026-55945) have issued software updates, and affected vendors awarded more than $20,000 in bug bounties.
Security researcher Gal Weizman of Forever Security has disclosed “BragJack,” an attack vector demonstrating that ordinary browser extensions can completely hijack the built-in AI agents of five major Chromium-based browsers without user interaction. Disclosed in September 2026, the technique compromises Google Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge Actions, Opera Neon, and Anthropic’s Claude in Chrome extension. By exploiting the architectural separation between an AI model’s interface and privileged browser components, BragJack allows an installed extension to bypass prompt injection defenses, read local files, capture screenshots, and execute autonomous tasks. The research generated two common vulnerabilities and exposures—CVE-2026-0628 in Chrome and CVE-2026-55945 in Edge—and over $20,000 in bug bounties following vendor remediation.
Architectural flaws in browser AI integrations
The vulnerability stems from how modern browsers integrate agentic AI features. To execute tasks on a user’s behalf, browser developers divide the agent into two distinct systems: an AI “brain” running as a web application or cloud service (such as gemini.google.com or perplexity.ai), and a privileged native “body” embedded in the browser (such as chrome://glic or built-in extension bridges). The body holds native operating system and browser privileges—opening tabs, capturing screenshots, accessing media streams, and reading local file paths via file:/// URIs.
Weizman discovered that this boundary collapses under Chromium’s declarativeNetRequest (DNR) API. Extensions with standard network permissions can alter HTTP response headers and redirect script requests without user interaction. Through a technique Weizman calls “DiNneR Serving,” an extension strips Content Security Policy (CSP) headers and cross-origin restrictions from the agent’s web context, redirecting benign JavaScript resources to attacker-controlled payloads.
In Google Chrome’s implementation, while direct script injection into the internal chrome://glic body is forbidden, the browser allowed extensions to intercept requests made by the embedded WebView hosting Gemini. By redirecting a Google static script (lazy.min.js) and modifying isolation headers, the researcher executed arbitrary code inside gemini.google.com within the privileged WebView. This script sent internal postMessage commands directly to chrome://glic, retrieving tab contents, extracting browser profile identities, rendering local PDF files, and gaining silent access to media permissions. Google registered the finding as CVE-2026-0628 with a high severity score of 8.8.
Prompt Forcing weaponizes legitimate agent permissions

Unlike traditional indirect prompt injection, where attackers hide adversarial instructions inside untrusted web pages hoping an LLM reads them, BragJack utilizes “Prompt Forcing.” Instead of attempting to trick model guardrails, the attacker supplies the full prompt and task sequence directly to the agent’s internal control channel. Because the instruction originates from what the browser body considers its trusted brain, the agent translates the instructions directly into authenticated browser actions.
In Perplexity Comet, the browser agent extension trusted several testing endpoints in its externally_connectable manifest. Using DNR to strip redirect headers from testing.perplexity.com, Weizman attached a content script that dispatched CALL_TOOL and START_AGENT commands to the internal agent. The agent was forced to open local file URLs (bypassing filters using mixed-case FiLe:///), extract browser history, summarize emails, and transmit stolen data to an external address.
Microsoft Edge presented an architectural variant: Microsoft separated its Copilot browser agent into distinct “Think” and “Do” states to prevent simultaneous unvetted instruction processing and action execution. However, an Edge marketing page exposed an internal API (edgeMarketingPagePrivate.sendCopilotQuery) to populate sample prompts. Weizman used extension debugger permissions to synthesize required user interaction tokens, then exploited a timing race condition in copilotLabPrivate.enableEdgeTools. By disabling tools immediately before sending the prompt and re-enabling them before the runtime verified state, the extension forced executable prompts against the system. Microsoft tracked the issue as CVE-2026-55945.
| Browser / Target | Architecture Model | Vulnerability Mechanism | Demonstrated Impact | Remediation & Bounty |
|---|---|---|---|---|
| Google Chrome (Gemini Live) | Privileged WebView (chrome://glic) |
DNR header stripping and script redirection (CVE-2026-0628) | Local file access, tab screenshots, profile leakage, mic and camera access | Patched in v143.0.7499.192; $7,000 bounty |
| Perplexity Comet | Built-in extension with trusted web origins | Overly broad externally_connectable domains and 302 stripping |
Email summarization exfiltration, history scraping, local file reads | Vendor patched; $7,000 bounty |
| Microsoft Edge (Copilot Actions) | Side panel iframe via edge://discover-chat |
Marketing API exposure, synthetic gestures, race condition (CVE-2026-55945) | Prompt forcing, arbitrary web actions, external data exfiltration | Patched in v150.0.4078.48; $5,000 bounty |
| Opera Neon | Built-in extension with trusted web origins | Unrestricted content script attachment on opera.com with CSP stripping |
Full browser agent hijack, autonomous web actions | Vendor patched; $900 bounty |
| Claude in Chrome | Third-party Chromium browser extension | DOM injection on onboarding page coupled with synthesized clicks | Side panel prompt forcing, automated agent workflow execution | Vendor patched; $600 bounty |
Enterprise fleet impact and flaw remediation
The findings published by Forever Security alter endpoint defense assumptions for enterprise fleets. Historically, browser extension isolation ensured that a malicious extension could manipulate DOM elements or eavesdrop on specific website sessions, but could not escape sandbox boundaries to inspect local disk structures or invoke system hardware without explicit permissions.
When browser vendors grant internal AI agents native capabilities to read files, manage active sessions, and execute user-level clicks, a compromised extension no longer needs native exploitation binaries. It simply instructs the browser’s built-in assistant to gather the data. This development illustrates why security through obscurity in enterprise systems fails when autonomous agents interface with legacy trust assumptions.
As confirmed in reporting by BleepingComputer, all five vendors resolved the specific flaws prior to disclosure, paying a cumulative total of more than $20,000 in bug bounties. Google fixed the WebView DNR bypass in Chrome version 143.0.7499.192, and Microsoft resolved the Copilot race condition in Edge version 150.0.4078.48. Anthropic and Opera updated their respective web-extension messaging boundaries.
What happens next
While the identified implementation vulnerabilities have been patched, the structural friction between web extensions and agentic browsers remains an active challenge for IT security teams. Chromium engineering teams are reviewing permission boundaries to restrict how declarativeNetRequest rules interact with embedded browser WebViews and internal company origins.
For enterprise IT administrators and security leaders, the immediate priority is verifying fleet patch levels and tightening extension governance:
- Verify that all endpoints running Google Chrome are updated to version 143.0.7499.192 or higher, and Microsoft Edge installations are at version 150.0.4078.48 or higher.
- Audit existing extension manifests across company devices, flagging tools requesting broad host permissions (
https://*/*) ordeclarativeNetRequestcapabilities. - Enforce strict extension allowlisting via group policy or mobile device management rather than relying on standard end-user permission prompts.
- Evaluate whether internal AI browser assistants should have file system access or autonomous click capabilities enabled by default in enterprise profiles.
Defenders must monitor future Chromium updates as browser architectures evolve toward formal isolation models for agentic execution runtimes.


