Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-20 · updated: 2026-09-20 · tags: [incident, retail] · confidence: high · severity: medium · affected_sectors: [retail] · au_impact: true

Researcher Gal Weizman of Forever Security disclosed BragJack, an attack technique that hijacks the AI assistants built into major browsers using one malicious browser extension, demonstrated against Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon and Anthropic's Claude in Chrome. The research earned more than US$20,000 in bug bounties from the five vendors, ranging from US$600 to US$7,000, and produced two CVEs. It requires the extension to already be installed, but then runs without user interaction, abusing the extension's ability to manipulate the traffic and pages that browsers' privileged AI components trust — in every case via Chromium's declarativeNetRequest functionality, which can rewrite response headers and redirect resources. Against Chrome, the researcher weakened security headers and redirected a JavaScript resource to execute code in the embedded Gemini web app's context, reaching Chrome's privileged AI component directly and seizing the ability to read local files, reach web content, take screenshots and potentially access the camera and microphone; Google assigned CVE-2026-0628 and paid US$7,000. The agentic browsers were worse: on Comet, an agent extension trusted a Perplexity testing domain that lacked the protections of the main site, and Weizman demonstrated forcing the agent to visit Perplexity, summarise the victim's emails and send the results to another address. Both Google and Microsoft have fixed the flaws assigned to them.

Attribute Detail
**Sector Retail & Entertainment & Sport
**Date 2026-09-20
**Source Forever Security
**Reliability Tier 1
**CVEs CVE-2026-0628