Researchers Found AI Assistants Vulnerable to Hijacking
Security researchers identified methods for malicious browser extensions to compromise AI assistants by intercepting internal browser traffic.
Updated on Sept. 28, 2026 in Artificial Intelligence

Live Poll
Do you trust AI assistants in your web browser to protect your private data?
Security researcher Gal Weizman uncovered vulnerabilities allowing malicious browser extensions to hijack AI assistants like Google Gemini and Claude. These findings, which resulted in security patches from Google and Microsoft, remain at the research stage and have not been reported as exploited in the wild.
Why it matters
AI assistants often rely on privileged internal browser components to execute tasks, which can be manipulated if an extension intercepts those connections. This discovery highlights the security risks inherent in integrating AI capabilities directly into browser architectures.
Google awarded $7,000 for CVE-2026-0628, while Microsoft addressed a race condition—a timing flaw where system operations occur in an unintended sequence—in Edge versions prior to 150.0.4078.48.
The players
Gal Weizman
Security researcher who identified the BragJack methods for compromising AI assistants.
Developer of the Chrome browser and the Gemini AI model, maintaining extensive bug bounty programs for security disclosures.
Microsoft
Developer of the Edge browser and integrated AI services, focused on securing web-based interaction layers.
Anthropic
AI research lab and developer of the Claude assistant that provides integrated browser-based features.
The details
The BragJack research demonstrated that malicious extensions leverage the Chromium declarativeNetRequest system, a feature designed to block or modify network requests, to intercept communication between the AI assistant and the browser. By exploiting a race condition, attackers can inject prompts and trigger actions before the browser completes its internal security verification processes. This unauthorized access potentially allows for the extraction of local files, browser profile data, and screenshots.
Timeline
2026: Security researchers published the BragJack findings.
- 2026-09-28
Researchers confirmed the vulnerability disclosures and associated bounty payments.
The Tech Race
This research follows a pattern of identifying new attack vectors in the bridge between web extensions and advanced browser-based AI features. It marks a critical pivot point for browser security as vendors race to isolate AI processes from traditional extension privileges.
Users can protect their data by ensuring their browser is updated to the latest version to apply vendor patches. Those who frequently use AI assistants within Chrome or Edge should audit installed extensions to remove any untrusted or unnecessary software that could exploit these vulnerabilities.
The takeaway
These findings underscore the necessity of robust sandbox architectures as AI assistants gain deeper access to local user environments. Users should monitor future browser update logs for additional patches related to CVE-2026-0628 and CVE-2026-55945 as vendors continue to secure their AI integration layers.
Further reading
For broader context on current safety protocols in the industry, explore our coverage of Artificial Intelligence.
Live Poll
Do you trust AI assistants in your web browser to protect your private data?






