AI Governance Institute
← News
Research2026-09-19

BragJack Attack Turns Browser Extensions Into AI Agent Hijack Tools

What happened

Security researcher Gal Weizman of Forever Security published findings on a new attack class he named BragJack, detailed by Bleeping Computer in BragJack attacks hijack AI browser agents through malicious extensions. The technique exploits Chrome's built-in declarativeNetRequest functionality, which extensions can access without elevated permissions, to inject prompts directly into AI agent components running inside the browser. Affected platforms include Chrome, Edge, Perplexity Comet, Opera Neon, and Claude for Chrome, covering a wide swath of enterprise AI browser deployments. Once injected, a hijacked agent can autonomously read local files, capture screenshots, access full browsing history, and send emails on behalf of the logged-in user. The attack does not require malware in the traditional sense. It weaponizes the AI agent's own trusted privileges, making it difficult to distinguish malicious from legitimate agent activity in endpoint telemetry.

Why it matters

  • ·AI browser agents are routinely granted access to email, files, and browsing history, but most enterprise permission manifests were never formally scoped for adversarial misuse. BragJack shows that an attacker needs only a plausibly legitimate extension to redirect those privileges, putting data access controls and agent permission boundary governance under immediate pressure.
  • ·Existing endpoint detection tools look for conventional malware signatures and anomalous process behavior. Because BragJack operates entirely through the browser's own extension and AI agent infrastructure, it produces no signals that current endpoint controls are tuned to catch. Compliance teams relying on endpoint security as a compensating control for AI agent risk should treat that assumption as broken.
  • ·Any organization that has deployed AI browser agents without a formal extension intake review process, agent-specific behavioral monitoring, or scoped permission manifests now faces a material gap. This is not a theoretical edge case; the affected platforms are widely used in enterprise environments, and the attack method is now publicly documented.

Governance controls affected

What to do now

  • ☐Audit all browser extensions currently approved for enterprise endpoints and flag any with declarativeNetRequest permissions as requiring re-evaluation against BragJack exposure.
  • ☐Review the permission scope granted to each deployed AI browser agent, specifically access to local files, email, screenshots, and browsing history, and document whether those scopes are necessary and monitored.
  • ☐Update behavioral anomaly detection baselines to flag unusual agent-initiated actions such as bulk file reads, screenshot capture, or outbound email initiated without a user-visible trigger.
  • ☐Require a formal agent permission boundary assessment for every AI browser agent before continued or new deployment, using the BragJack disclosure as a minimum threat scenario.
  • ☐Engage browser agent vendors (Perplexity, Opera, Anthropic for Chrome) to confirm whether mitigations are in development and incorporate their timelines into your change management tracking.

What to watch next

Compliance teams should monitor whether affected vendors publish architectural mitigations or permission-scoping changes in response to the BragJack disclosure, as no fix for the underlying Chromium mechanism has been announced. The disclosure arrives alongside a widening pattern of agent-layer attacks, including unpatched zero-click prompt injection hitting ChatGPT Atlas and Claude browser agents and hidden HTML prompt injection defeating AI email summarizers with 100% success. Regulators in the EU examining agentic AI deployments under the EU AI Act Governance and Enforcement Framework may treat inadequate agent permission scoping as a documentation and oversight failure. Enterprise teams should also watch for insurance underwriters and auditors beginning to ask specifically about browser extension governance as part of AI agent risk assessments.

Related Coverage

Research2026-10-08

JavaScript Obfuscation Defeats Manus Agent Defenses, Exposing Inspection-Only Controls

Salt Labs researchers bypassed prompt-injection defenses in the Manus AI agent by hiding instructions inside an email using JavaScript obfuscation. The agent decoded and acted on those hidden instructions without detecting the attack. The finding shows that content inspection alone cannot protect agents that can run code or take actions based on untrusted input.

Research2026-10-03

Orchestration Framework Flaws Make AI Workflow Pipelines a Primary Attack Target

Research published by Help Net Security finds that agent orchestration frameworks including Flowise and Langflow are among the most actively targeted systems in current vulnerability disclosures. Attackers use prompt injection and manipulated workflow configuration files to reach code execution points inside enterprise AI pipelines. Organizations running agentic workflows need isolation, configuration validation, and red-team coverage at the orchestration layer, not just at the model level.

Research2026-10-01

Akamai: MCP Attack Surface Requires Zero Trust Controls and Machine Identity Governance

Akamai published a research report arguing that the Model Context Protocol (MCP) has become a significant enterprise attack surface. MCP is the standard that lets AI agents connect to external tools and systems. The report finds that malicious MCP servers can manipulate AI agent behavior through prompt injection and cross-server attacks. Akamai calls for organizations to inventory MCP servers, enforce least-privilege permissions, govern machine identities, and monitor autonomous agent activity.