BragJack: one extension hijacks built-in AI agents in Chrome, Edge, Comet, Opera Neon, Claude
Forever Security (16 September 2026; also The Hacker News) documents BragJack: a research technique where a malicious Chromium extension with common page-modify and declarativeNetRequest permissions injects into the trusted origin the browser AI "body" listens to, then commands the built-in assistant. Affected demos: Gemini Live in Chrome (CVE-2026-0628, CVSS 8.8 per CISA score cited by researchers; fixed in Chrome 143.0.7499.192, Jan 2026), Microsoft Edge (CVE-2026-55945, CVSS 4.2; fixed in Edge 150.0.4078.48, 2 Jul 2026), Perplexity Comet, Opera Neon, and Claude in Chrome (latter three without CVE; vendor bounty acknowledgements claimed). Impacts vary by product (agent hijack, local file read, camera/mic on Chrome). Researcher demos only — not reported in the wild; requires the attacker's extension already installed. Primary: Forever Security; wire: The Hacker News.
- Product
- Built-in browser AI assistants (Chrome Gemini Live; Edge; Perplexity Comet; Opera Neon; Claude in Chrome)
- Versions
- Chrome fixed CVE-2026-0628 in 143.0.7499.192; Edge fixed CVE-2026-55945 in 150.0.4078.48; Comet/Opera Neon/Claude in Chrome: see vendor guidance / Forever Security write-up
- CVSS
- 8.8 (CVE-2026-0628, CISA-scored per Forever Security); 4.2 (CVE-2026-55945)
- Exploited in Australia?
- unknown
- Patch to
- Update Chrome/Edge to fixed builds; restrict extension install (allow lists); treat browser AI agent surfaces as high-privilege; review Forever Security mitigations
Primary: Forever Security — BragJack research (16 Sep 2026) · Vendor: Forever Security · CVE: CVE-2026-0628, CVE-2026-55945 · The Hacker News — AI assistant extension hijack (16 Sep 2026)
