BragJack Attack Turns Browser Extensions Into AI Agent Hijack Tools
Source
BragJack attacks hijack AI browser agents through malicious extensionsForever Security / Bleeping Computer
What happened
Security researcher Gal Weizman of Forever Security published findings on a new attack class he named BragJack, detailed by Bleeping Computer in BragJack attacks hijack AI browser agents through malicious extensions. The technique exploits Chrome's built-in declarativeNetRequest functionality, which extensions can access without elevated permissions, to inject prompts directly into AI agent components running inside the browser. Affected platforms include Chrome, Edge, Perplexity Comet, Opera Neon, and Claude for Chrome, covering a wide swath of enterprise AI browser deployments. Once injected, a hijacked agent can autonomously read local files, capture screenshots, access full browsing history, and send emails on behalf of the logged-in user. The attack does not require malware in the traditional sense. It weaponizes the AI agent's own trusted privileges, making it difficult to distinguish malicious from legitimate agent activity in endpoint telemetry.
Why it matters
- ·AI browser agents are routinely granted access to email, files, and browsing history, but most enterprise permission manifests were never formally scoped for adversarial misuse. BragJack shows that an attacker needs only a plausibly legitimate extension to redirect those privileges, putting data access controls and agent permission boundary governance under immediate pressure.
- ·Existing endpoint detection tools look for conventional malware signatures and anomalous process behavior. Because BragJack operates entirely through the browser's own extension and AI agent infrastructure, it produces no signals that current endpoint controls are tuned to catch. Compliance teams relying on endpoint security as a compensating control for AI agent risk should treat that assumption as broken.
- ·Any organization that has deployed AI browser agents without a formal extension intake review process, agent-specific behavioral monitoring, or scoped permission manifests now faces a material gap. This is not a theoretical edge case; the affected platforms are widely used in enterprise environments, and the attack method is now publicly documented.
Governance controls affected
What to do now
- ☐Audit all browser extensions currently approved for enterprise endpoints and flag any with declarativeNetRequest permissions as requiring re-evaluation against BragJack exposure.
- ☐Review the permission scope granted to each deployed AI browser agent, specifically access to local files, email, screenshots, and browsing history, and document whether those scopes are necessary and monitored.
- ☐Update behavioral anomaly detection baselines to flag unusual agent-initiated actions such as bulk file reads, screenshot capture, or outbound email initiated without a user-visible trigger.
- ☐Require a formal agent permission boundary assessment for every AI browser agent before continued or new deployment, using the BragJack disclosure as a minimum threat scenario.
- ☐Engage browser agent vendors (Perplexity, Opera, Anthropic for Chrome) to confirm whether mitigations are in development and incorporate their timelines into your change management tracking.
What to watch next
Compliance teams should monitor whether affected vendors publish architectural mitigations or permission-scoping changes in response to the BragJack disclosure, as no fix for the underlying Chromium mechanism has been announced. The disclosure arrives alongside a widening pattern of agent-layer attacks, including unpatched zero-click prompt injection hitting ChatGPT Atlas and Claude browser agents and hidden HTML prompt injection defeating AI email summarizers with 100% success. Regulators in the EU examining agentic AI deployments under the EU AI Act Governance and Enforcement Framework may treat inadequate agent permission scoping as a documentation and oversight failure. Enterprise teams should also watch for insurance underwriters and auditors beginning to ask specifically about browser extension governance as part of AI agent risk assessments.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
