Abstract layered privacy tunnel with a diverging browser network path
Browser Privacy Published 17 Sept 2026 3 min read2 sources

BragJack: Why AI Browser Users Should Audit Extensions

New BragJack research shows how a malicious extension could cross into privileged browser AI features. The reported flaws have been resolved, but the practical lesson remains: update the browser and be selective about extensions and connected accounts.

By VPN Rocks Editorial Team

The short version

What you need to know

  • The 16 September research covers Chrome with Gemini, Edge, Opera Neon, Perplexity Comet and Claude in Chrome; the demonstrated capabilities differ by environment.
  • These are proof-of-concept findings involving a malicious extension, not evidence that every AI-browser user was compromised. Dark Reading reports that the individual issues have been resolved.
  • Update the browser and AI extension, remove unnecessary add-ons, and limit sensitive account access. A VPN cannot stop an installed extension abusing permissions inside the browser.

What the new research demonstrates

Forever Security published its BragJack research on 16 September, describing related weaknesses across five browser-AI environments. The common problem was a trust boundary: an extension could interfere with a web surface trusted by a privileged browser component or assistant.

The report builds on the earlier Chrome/Gemini finding called GlicJack and expands the investigation to Opera Neon, Microsoft Edge, Claude in Chrome and Perplexity Comet. The fresh angle is that cross-product pattern, not a claim that all five bugs were first discovered this week.

The researchers describe attacks using an installed malicious extension. Their zero-click wording refers to the demonstrated exploitation after that prerequisite; it does not mean a stranger could reach a clean browser merely because its owner had any harmless extension installed. Claude in Chrome is itself an extension, not a separate browser, and the report explicitly distinguishes that extension-to-extension case.

Not every browser exposed the same data

Forever Security's results table lists local-file access and screenshot capability for Chrome and Comet, but not for Edge, Opera Neon or Claude in Chrome. Camera and microphone access are listed for Chrome only. Those findings should not be flattened into a claim that every tested assistant could read local files or activate a camera.

For several environments, the researchers describe sending instructions directly to the agent rather than hiding a malicious instruction in a document and hoping it would be followed. They call this prompt forcing. Their Chrome example instead took control of the privileged browser-side component; their table does not mark Chrome as a browser-agent hijack.

Dark Reading describes the work as proof-of-concept research and reports that the individual issues have since been resolved. Neither source cited here establishes a real-world victim count for BragJack. The research is a reason to update and review access, not a breach notification for everyone using browser AI.

What to check in your browser today

Use the browser's own update page, install available updates and relaunch when asked. Check updates for a separately installed AI extension too. This article does not supply a single fixed-version number across five different products: the reporting covers different vulnerabilities and remediation paths.

Open the extensions manager and remove add-ons you no longer need or cannot account for. Review which remaining extensions can read or change website data, and restrict access where the browser supports it. An official-store listing is a useful installation route, not a guarantee that an extension will remain trustworthy forever.

Before letting an assistant act in email, shopping or work accounts, consider whether it needs that access. For experimentation, a separate browser profile without sensitive signed-in accounts can reduce what is available there; it is a precaution, not a patch or a guaranteed security boundary. On a managed device, follow the organisation's approved-browser and extension policy.

Why encrypted traffic does not solve this

A VPN can protect supported traffic on its journey to the VPN server, but an extension operates inside the browser where pages and account sessions are already available. Encrypting the network connection does not revoke extension permissions, repair a browser trust boundary or prevent an assistant carrying out an unwanted action.

Our earlier clipboard-stealing VPN-extension report covers a different mechanism, but the same reason to inspect installed add-ons instead of trusting a privacy label. For BragJack, the useful response is current software and narrower browser access, not buying an extra VPN.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps