TL;DR: A single browser extension took control of AI assistants in five browsers with built-in AI. No phishing email. No stolen password. No user click once the extension was installed. Researchers call the technique BragJack, and it can turn a helpful AI agent into a tool for stealing your files, screenshots, and data.
What Happened?
One extension. Five hijacked AI agents.
BragJack never breaks the AI model or hides a secret prompt. It rides a trusted channel from a low level extension straight into a high privilege agent.
Because a legitimate agent runs the final action, classic malware scanners and model safety filters both miss it.
Security researchers published a proof of concept this month showing how one malicious extension could seize the AI agents in five Chromium-based browsers. It asked only for the permissions people hand an ad blocker every day.
The method is new enough to earn its own name: Prompt Forcing. Regular prompt injection hides instructions inside a webpage and hopes the AI reads them by mistake. Prompt Forcing is more direct. The attacker hands the AI agent a full set of commands, and the agent runs them with the access it already has.
The extension abused a standard browser feature that ad blockers use to filter network requests. That let it cross the line meant to keep untrusted extensions away from the far more powerful AI agent. One extension worked on all five browsers.
What’s the Impact?
What one extension could reach.
No real world attacks have been seen yet. But the method is public and reproducible, which is exactly why patching and extension hygiene matter now.
Once inside, the agent could read local files, pull browsing data, capture screenshots, and, in some cases, access the camera and microphone. On browsers whose AI can act on websites, the agent could be told to do something ordinary, like summarize recent emails, then quietly ship that data out.
The tricky part is how normal it looks. Because the AI acts with legitimate privileges, the activity reads like software doing its job, so tools that watch for classic malware can miss it. Safety filters inside the AI model cannot help either, since the weakness is in how the agent trusts its own channels.
Five vendors paid more than $20,000 in bug bounties, from $600 up to $7,000. Two flaws got CVE identifiers and are already patched. No real-world attacks have been reported, but the method is fully documented, so others can copy it.
The Safest AI Agent Is a Governed One
BragJack shows what happens when AI gets broad power with no rules around how it uses it. For any company rolling out agentic AI, the answer is governance: clear limits, human approval on risky actions, and a record of what the agent did.
- Scope each AI teammate to one function and one environment, so it never gets open-ended reach.
- Set explicit permissions for what it can read, write, and run, and raise them only as trust grows.
- Put consequential actions behind a human approval gate, so nothing risky moves on its own.
- Keep a full log of every recommendation, approval, and action for audit and review.
- Test your own defenses with offense first, so exploitable gaps show up before an attacker does.
How to Avoid This
No public indicators of compromise exist yet, since this is proof-of-concept research and no live campaign has been seen. Detection should focus on behavior, not file signatures.
- Update every browser to the latest version. The two patched flaws are tracked as CVE-2026-0628 and CVE-2026-55945.
- Review your installed extensions and remove anything you do not recognize or no longer use.
- Treat broad permission requests as a red flag. Access to all sites and debugger rights are powerful, so grant them only to software you trust.
- On browsers with a built-in AI agent, limit what it can reach and turn off features you don’t need.
- Watch for AI actions that do not fit normal use, like an agent pulling data or hitting sites for no clear reason.