BragJack attacks hijack AI browser agents through malicious extensions
AI Summary
Security researcher Gal Weizman discovered a new attack technique called BragJack that hijacks AI browser agents through malicious browser extensions. The proof-of-concept targets AI assistants in Chromium-based browsers including Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome by exploiting trust relationships and browser extension capabilities. The attacks use declarativeNetRequest (DNR) rules to manipulate trusted components, enabling unauthorized access to sensitive data and control over AI agents without user interaction. The technique, dubbed 'Prompt Forcing,' allows attackers to send full prompts and instructions to the AI agent, leveraging its legitimate privileges to perform malicious actions.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | perplexity[.]ai | Details → |