MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-19 · via BleepingComputer

Malicious browser extensions can seize control of built-in AI assistants, researcher finds

Image via BleepingComputer
Image via BleepingComputer

Security researcher Gal Weizman demonstrated a proof-of-concept attack, named BragJack, that uses a single malicious browser extension to hijack AI assistants in five Chromium-based browsers, including Chrome's Gemini Live and Microsoft Edge. The attack exploits the declarativeNetRequest feature to intercept and manipulate network requests, allowing the extension to execute code within the AI's privileged context without user interaction. The researcher earned over $20,000 in bug bounties and two CVEs were issued, with Google and Microsoft already patching their respective flaws.

Expanded Detail

The attack technique spans five Chromium-based targets, with bounties ranging from $600 to $7,000 per vendor. Weizman's approach leverages declarativeNetRequest to intercept network traffic, weakening security headers and redirecting JavaScript resources to execute code within privileged AI contexts. The researcher conceptualizes browser AI systems as comprising a decision-making model and a privileged execution layer that handles tabs, screenshots, and site interactions. Microsoft's split Think/Do modes were bypassed via a race condition, while Perplexity's testing domain lacked the protections of its primary site.

Context

This research highlights how browser extensions, long a vector for credential theft and ad fraud, now threaten AI assistants with expanded system access. Users who install extensions from unofficial sources may face silent data exposure, as attacks require no interaction once the extension is present. The findings could push vendors to harden AI components and reconsider extension permissions, though smaller browsers may lag in patching.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Google patches Pixel modem flaw under active targeted exploitation · Cybersecurity
KREMLIN toolkit exploits Chromium integrity to silently inject credential-stealing extensions · Cybersecurity
CISA flags actively exploited ScreenConnect bug, orders federal fixes · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “BragJack attacks hijack AI browser agents through malicious extensions.” Browse more stories.