AI assistants are increasingly integrated into the web browsers we use daily. They can summarize content, provide explanations, and at times, perform actions on websites, granting them levels of access that typical web pages wouldn’t have. Security researcher Gal Weizman from Forever Security has uncovered how a malicious browser extension could exploit these powerful AI functionalities. His project, referred to as BragJack, assessed vulnerabilities in popular tools like Gemini Live in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon, and Anthropic’s Claude in Chrome, leading to over $20,000 in bug bounties and two identified CVEs.
Before jumping to conclusions, it’s essential to note that these attacks required the malicious extension to be installed beforehand. Weizman demonstrated that these attacks didn’t need any further clicks from the affected users. So, how does one extension manage to penetrate the browser so deeply? It all relates to the way these AI assistants operate.
Weizman characterizes these AI systems as possessing both a “brain” and a “body.” The AI model determines the actions, while a privileged component within the browser executes those actions. Depending on the AI product, this privileged component can read webpage content, capture screenshots, or interact with various sites. This arrangement poses risks if another element in the browser can manipulate the connection between these components. The attacks predominantly exploited the DNR (declarativeNetRequest) system of Chromium, which allows extensions to alter network requests — this includes modifying response headers or redirecting resources.
One notable exploit involved Chrome’s Gemini interface. Researchers found that, despite Chrome’s safeguards preventing extensions from injecting scripts directly into its pages, extensions could still modify certain network requests related to the Gemini experience. This loophole permitted Weizman to attain browser functionalities that the extension shouldn’t have had access to, enabling him to retrieve local files, capture screenshots, and even activate the camera and microphone without user interaction. Google acknowledged the vulnerability and rewarded the researchers with a $7,000 bounty, identifying it as CVE-2026-0628. They’ve since confirmed that a patch was released to close this security hole on the Gemini side panel.
Perplexity Comet raised additional concerns because its AI agent can operate within websites. Weizman discovered that Comet’s internal agent trusted various Perplexity domains, including one testing domain lacking the same security protections. By using DNR to bypass the redirection to this domain, the malicious extension could interact with Comet’s agent, allowing access to browsing history, screenshots, and local files. In a concerning demonstration, Weizman directed the agent to access Perplexity, summarize recent emails, and send that information to another address.
In Microsoft Edge, where there are built-in protections against unauthorized prompts, researchers found a way to circumvent these safeguards through a timing flaw, known as a race condition. This allowed the extension to prompt the AI before Edge could complete its security checks. Microsoft documented this vulnerability as CVE-2026-55945, designating it with medium severity, and they recommend users update their Edge browsers to close this security gap.
Related vulnerabilities were also identified in Opera Neon and Claude in Chrome, with Claude functioning as a browser extension. Researchers demonstrated exploits that allowed manipulation of Claude’s prompts via trusted domains, while Opera allowed similar access to its AI agent. All five case studies were based on Chromium, which facilitated the use of a similar attack methodology across different browsers.
The findings highlight the significant risks associated with browser extensions, which many of us may overlook. Weizman’s term “Prompt Forcing” refers to a novel attack method whereby attackers can inject commands into trusted channels, enabling the AI to execute potentially harmful actions. This complicates the security landscape, as malicious behavior might appear similar to typical browser activity.
This situation prompts a need for caution regarding browser extensions. If you’ve added extensions in the past, it may be time to review them. Removing unneeded or unrecognized extensions can minimize risks and simplify your browsing experience. Here are a few suggestions for maintaining browser security:
Ensure your browser is updated regularly to incorporate security fixes.
Uninstall unused extensions by checking your browser’s extension manager.
Evaluate permissions carefully before installing new extensions.
Limit access for extensions to necessary sites only.
Be cautious with AI extensions, as not all are developed by trusted companies.
Disable AI features you don’t actively use.
Use robust antivirus software to provide additional security layers.
Treat extensions like applications; don’t add them unless necessary.
These findings are a reminder of the increasing power and potential risks of AI in our browsers. The need for vigilant management of browser extensions becomes critical as AI developments continue to evolve. Would you trust an AI assistant with browser permissions if there’s a chance that its access could be exploited by a malicious extension? It’s worth pondering as we navigate our online experiences.





