BragJack Technique Hijacked AI Assistants in Five Browsers
The newly identified method exploits trusted browser communication channels to inject commands into AI assistants.
Updated on Sept. 19, 2026 in Artificial Intelligence

Live Poll
Do you trust that your browser extensions are not compromising your AI assistants' security?
Researchers identified a new attack technique called BragJack that allows malicious browser extensions to seize control of AI assistants. The threat impacts five major web browsers, including Chrome and Edge.
Why it matters
This vulnerability demonstrates how trusted communication channels can be manipulated to supply commands directly to privileged components within modern web browsers. It highlights the growing security risks associated with integrating AI-driven assistants into standard browsing environments.
The BragJack technique targets 5 browser platforms, including Chrome, Edge, Opera Neon, Comet, and Claude running within Chrome. The exploit operates by seizing trusted communication channels to inject commands directly into privileged browser components.
The players
Chrome
A web browser developed by Google that utilizes the Chromium engine and hosts a large ecosystem of third-party extensions.
Edge
The Microsoft-developed web browser that shares the Chromium base and features native integration with AI-powered features.
The details
BragJack works by exploiting the internal messaging architecture that AI assistants use to interact with the browser's core. By masquerading as a legitimate extension, the attacker gains access to privileged components, allowing them to bypass standard security filters. This process effectively turns the AI assistant into a proxy for executing arbitrary commands initiated by the malicious code.
Timeline
September 19, 2026: The research report documenting the BragJack technique was published.
The Tech Race
BragJack echoes earlier security research into malicious browser extensions that leveraged elevated permissions to perform unauthorized actions. It marks a shift in the security landscape where AI-specific integration points are now the primary target for persistent browser-based threats.
Users should review their currently installed browser extensions to ensure they only rely on trusted developers. Since the attack impacts five major browsers, users may need to wait for security patches or updates from their specific browser provider to mitigate the risk.
The takeaway
The BragJack exploit highlights a significant security gap in how browsers bridge the gap between third-party extensions and AI assistants. Users should monitor browser security bulletins for upcoming patches that address command injection vulnerabilities within these communication channels.
Further reading
For broader context on current risks to large language models and their integrations, visit our Artificial Intelligence section.
Live Poll
Do you trust that your browser extensions are not compromising your AI assistants' security?






