:

BRAGJACK ATTACK HIJACKS AI BROWSER AGENTS

AI DESK1 MIN READ
SAT, SEP 19, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A proof-of-concept attack called BragJack can hijack AI assistants across multiple browsers and platforms through a single malicious extension. Security researcher Gal Weizman from Forever Security demonstrated the vulnerability using a Prompt Forcing technique.

BragJack targets AI browser agents in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The attack works by injecting malicious prompts through a compromised extension, allowing attackers to manipulate how AI assistants respond to user queries. Weizman's research earned over $20,000 in bug bounties and resulted in two CVEs being assigned. The vulnerability highlights a critical security gap in how AI agents handle instructions from browser extensions with elevated permissions. The Prompt Forcing technique exploits the trust relationship between extensions and AI assistants, demonstrating that malicious code can intercept and modify AI behavior without user awareness. This raises concerns about extension security practices across major browser platforms and the need for stronger isolation mechanisms between extensions and AI systems.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Law enforcement agencies have issued a joint advisory detailing a sustained campaign by the North Korean hacking group WaterPlum, which compromised at least 30,000 devices worldwide and stole over $10.7 million in cryptocurrency between December 2025 and July 2026.

2H AGOSecurity Desk

If your PC is running slowly or behaving unusually, malware may be the culprit. Running a malware check is a straightforward way to diagnose and address the problem.

2H AGOSecurity Desk

A detailed investigation revealed that smart TVs from major manufacturers collect extensive user data, including audio recordings and viewing habits, even when devices appear powered off. The practice extends across the industry, not limited to LG.

2H AGOIndustry Desk

While AI labs debate slowing development, widely available AI tools are already uncovering a surge of software vulnerabilities at unprecedented scale.

5H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.