Darkreading BragJack Attack Compromises Major Browser AI Assistants
Article Content
- •BragJack exploits AI assistants in five major browsers.
- •The attack allows unauthorized access to sensitive user data.
- •Two CVEs were issued, and over $20,000 in bug bounties were awarded.
The BragJack attack exploits vulnerabilities in the AI assistants of five major browsers: Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. Researchers from Forever Security discovered that these vulnerabilities allow attackers to access sensitive data, control local files, and exfiltrate information through malicious browser extensions. The attack does not rely on traditional methods like prompt injection but instead leverages a critical design flaw in how browsers interact with extensions. This flaw allows untrusted extensions to hijack the communication channel with the browser's AI, leading to unauthorized actions. The research resulted in over $20,000 in bug bounties and the issuance of two CVEs: CVE-2026-0628 and CVE-2026-55945. All affected browsers have since patched the vulnerabilities. The attack poses a risk to millions of users globally who utilize these browsers with extensions installed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Anthropic and CVE-2026-0628 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…