Security researchers at Forever Security have revealed a vulnerability where a standard browser extension can take control of built-in AI assistants across multiple Chromium-based browsers. This includes Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension. The exploit allows the installed extension to access and manipulate the AI's functions.
Once installed, the malicious extension can drive the AI agent to act on behalf of an attacker in Comet, Edge, Opera Neon, and Claude in Chrome. In Chrome and Comet, the extension could also read files from the user's computer. Furthermore, in Chrome, it was demonstrated that the extension could activate the camera and microphone. These findings are researcher demonstrations and have not been observed in active attacks.
The AI assistants operate with a 'body' within the browser that handles actions like screen viewing, file access, and camera use, and a 'brain' on company servers that issues commands. The browser's AI 'body' is designed to only accept orders from a specific trusted web page, such as gemini.google.com for Chrome. Forever Security's method involves the extension seizing control of this trusted page, allowing it to send its own commands to the AI as if it were the legitimate vendor. The extension only requires two common permissions: one to change web pages and another for declarativeNetRequest, which modifies network traffic.
The vulnerability in Chrome was previously detailed in March as GlicJack and was fixed by Google in Chrome version 143.0.7499.192 in early January 2026, tracked as CVE-2026-0628 with a CISA rating of 8.8. The recent research by Forever Security expanded on this, identifying similar vulnerabilities in Comet, Edge, Opera Neon, and Claude in Chrome. The Edge finding received CVE-2026-55945, rated 4.2, and was fixed by Microsoft in Edge version 150.0.4078.48 on July 2. The Comet, Opera Neon, and Claude findings currently do not have CVEs.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security researcher Gal Weizman disclosed "BragJack," a new attack technique that uses malicious browser extensions to hijack AI assistants in popular Chromium-based browsers. This allows an extension to control the AI agent and potentially access sensitive information or act on the user's behalf, exploiting the way AI assistants are integrated with browser capabilities. Google and Microsoft have already resolved the reported flaws.
Security researchers at Forever Security demonstrated that a common browser extension could hijack AI assistants in five Chromium-based products, including Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension. This vulnerability allows an attacker's extension to control the AI agent, and in some cases, access user files or activate the camera and microphone, by impersonating the AI vendor's trusted web page.