Forever Security demonstrated extension-to-agent attacks across Chrome, Comet, Edge, Opera Neon and Claude in Chrome. Forever Security disclosed BragJack, a group of attacks in which an ordinary installed browser extension could cross into a privileged AI assistant. Researchers demonstrated variants against Gemini in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon and Claude in Chrome.
BragJack: verified facts
| Disclosed | September 16, 2026 | Forever Security |
|---|---|---|
| Affected class | AI assistants in five browser products | Forever Security; Hacker News |
| Assigned identifiers | CVE-2026-0628 and CVE-2026-55945 | Forever Security |
| Attack prerequisite | An installed ordinary browser extension | Forever Security; Canadian Cyber Security Journal |
What the update changes
Forever Security disclosed BragJack, a group of attacks in which an ordinary installed browser extension could cross into a privileged AI assistant. Researchers demonstrated variants against Gemini in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon and Claude in Chrome.
The impact was not identical across every product. Demonstrations included forcing prompts, reading local files or browser history, capturing screenshots and reaching camera or microphone capabilities. The research lists CVE-2026-0628 and CVE-2026-55945 alongside bug-bounty payments from affected vendors.
BragJack is distinct from a hidden instruction on an arbitrary webpage. The core trust problem is that an extension already running inside the browser can reach or influence an assistant that has broader context and authority. The agent can become a confused deputy for the extension.
The prerequisite still matters: an attacker needs an extension installed in the user profile. Enterprises should not interpret the research as a zero-install remote compromise. They should treat extension approval as software deployment, because a modest permission can become more powerful when a browser adds an embedded agent.
Defenders should inventory installed extensions, remove unused entries, restrict stores and developers, and review whether AI browser features are enabled. Patch status must be checked for each product because disclosure, vendor acknowledgement and a fully deployed fix are separate lifecycle points.
Browser vendors need stronger isolation between extensions and agent surfaces. An assistant should reject synthetic or unauthorised calls, minimise inherited permissions and require a trusted user confirmation before accessing files, sensors or authenticated actions. Logs should identify which extension influenced a request.
Security testing should include combinations rather than evaluating an assistant alone. A safe-looking agent can become dangerous when paired with another extension, a logged-in session and access to local data. Red teams should test cross-extension messages, injected scripts and background execution.
BragJack shows that browser AI expands the meaning of extension risk. Organisations should narrow extension trust now and verify vendor fixes, while product teams design agents as separate security principals instead of convenient features inside an already privileged browser.
Related Lapaas Voice coverage
Read our coverage of Cohere encrypted inference and NVIDIA CUDA-Q logical quantum codesign for adjacent context.
Frequently asked questions
What is BragJack?
Forever Security demonstrated extension-to-agent attacks across Chrome, Comet, Edge, Opera Neon and Claude in Chrome.
What changed?
The reported impact varied by product and included local files, history, screenshots, camera or microphone access.
What should users verify?
Researchers report two CVEs and bug-bounty payments; administrators should review extension trust and patch status.
Sources
- Forever Security — 2026-09-16
- The Hacker News — 2026-09-16
- Canadian Cyber Security Journal — 2026-09-16
- The Axe Report — 2026-09-16
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



