Tools AI Risk Radar ai-incident-0092
Incident record
One malicious extension hijacked the built-in AI agents in five browsers, including Claude in Chrome and Comet
- Severity
- High
- Status
- Proof-of-concept
- Type
- Agent Hijack
- Target
- Chrome with Gemini, Perplexity Comet, Microsoft Edge with Copilot, Opera Neon, Claude in Chrome
- Actor
- researcher
- CVE
- CVE-2026-0628
What happened
Researcher Gal Weizman showed that an extension using ordinary permissions can speak from the vendor page the in-browser half of an agent trusts. On Comet, Edge, Opera Neon and Claude in Chrome that meant issuing the agent instructions, such as opening a victim's email and forwarding the finance messages. On Chrome it meant driving the acting half directly, reading local files and switching on the camera and microphone.
Published as BragJack on 16 September 2026. All five vendors paid a bounty: $7,000 from Google and Perplexity, $5,000 from Microsoft, $900 from Opera and $600 from Anthropic. Two of the five carry CVE records that predate the disclosure, CVE-2026-0628 for Chrome, scored 8.8 and fixed in 143.0.7499.192, and CVE-2026-55945 for the Edge race condition, scored 4.2. Every version needs the attacker's own extension installed on the machine first, and the work is a demonstration rather than an attack seen in use.
Sources
- The BragJack disclosureforever.security/blog/bragjack-hijacking-5-browsers-via-buil…
- NVD record CVE-2026-0628nvd.nist.gov/vuln/detail/CVE-2026-0628
- NVD record CVE-2026-55945nvd.nist.gov/vuln/detail/CVE-2026-55945
- YFarmX: AI browsers comparedyfarmx.com/ai/agents/ai-browsers/#one-extension-hijacked-the…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026