YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0092

Incident record

One malicious extension hijacked the built-in AI agents in five browsers, including Claude in Chrome and Comet

Severity
High
Status
Proof-of-concept
Type
Agent Hijack
Target
Chrome with Gemini, Perplexity Comet, Microsoft Edge with Copilot, Opera Neon, Claude in Chrome
Actor
researcher
CVE
CVE-2026-0628

What happened

Researcher Gal Weizman showed that an extension using ordinary permissions can speak from the vendor page the in-browser half of an agent trusts. On Comet, Edge, Opera Neon and Claude in Chrome that meant issuing the agent instructions, such as opening a victim's email and forwarding the finance messages. On Chrome it meant driving the acting half directly, reading local files and switching on the camera and microphone.

Published as BragJack on 16 September 2026. All five vendors paid a bounty: $7,000 from Google and Perplexity, $5,000 from Microsoft, $900 from Opera and $600 from Anthropic. Two of the five carry CVE records that predate the disclosure, CVE-2026-0628 for Chrome, scored 8.8 and fixed in 143.0.7499.192, and CVE-2026-55945 for the Edge race condition, scored 4.2. Every version needs the attacker's own extension installed on the machine first, and the work is a demonstration rather than an attack seen in use.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026