Researchers from Forever Security have uncovered a method by which malicious browser extensions can exploit the artificial intelligence (AI) features of Chromium-based browsers—like Chrome and Edge—to access sensitive data and perform actions on behalf of users. The study tested AI agents across five different Chromium environments, including Chrome, Edge, Comet, Opera Neon, and Claude in Chrome. The team developed an attack technique named BragJack, which repurposes the commands used by AI assistants such as Gemini in Chrome and Copilot in Edge, Comet, Opera Neon, and Claude in Chrome.
The attack requires that a malicious extension is already installed in the browser and does not directly compromise remote users. The researchers took advantage of the ability of Chromium extensions to modify how network requests are processed. In Chrome, they altered the protections of the Gemini application embedded in the browser, repurposing one of the scripts it loads to execute their own code. This allowed them to send commands that the browser executed as if they came from the AI assistant, enabling them to open pages, access local files, read PDFs, and even take screenshots.
On Comet, the researchers exploited a vulnerability in how the browser handled trusted domains. They found that the AI agent would accept commands from various Perplexity domains, including a less secure test domain. Using their extension, they prevented the test domain from redirecting to the main Perplexity site, injected their code, and sent instructions directly to the AI agent. In a proof of concept, they prompted Comet to check the five most recent emails from a test account, summarize them, and send the results to another email address.
The researchers named this broader technique "Prompt Forcing," which differs from traditional prompt injection attacks. Instead of hiding malicious instructions within content that the AI might process, attackers directly send commands to the AI agent, which then executes them based on the permissions it already holds within the browser. This research led to the identification of two security vulnerabilities, CVE-2026-0628 for Chrome and CVE-2026-55945 for Edge, both of which had been fixed before the research was published. Forever Security also awarded over $20,000 in bounties to the researchers involved, including $7,000 each for Chrome and Comet.
While BragJack is currently only a documented proof of concept, it highlights the risks associated with browser extensions and the AI features they may access. The attack requires a malicious extension to already be installed, but the technique could be replicated by attackers. Users are advised to be cautious about the extensions they install, ensuring they come from trusted sources and request only necessary permissions. Regularly reviewing and removing unused or untrusted extensions is also recommended. Keeping browsers updated with the latest security patches is crucial, as is limiting the access granted to AI assistants—especially when they involve local files, connected accounts, or direct website actions. The more access an AI agent has, the greater the potential damage if it is compromised.
Researchers Demonstrate Browser AI Exploitation Through Malicious Extensions
AI-rewritten from original reportingHow it works
ai-hijackbrowser-securitymalicious-extensionschromiumcvesecurity-research
Original sources:
- 🇫🇷Clubic



