THE TELL

BragJack: one extension, five AI browsers, and an inbox summarized for a stranger

A researcher installed a single malicious extension, told the browser's own AI assistant to read the owner's email, and had the summary mailed to another address. The same extension worked on five different browsers.

The AI helper now built into your browser can see the page you see, take a screenshot of it, open tabs for you and, in some cases, reach files on your computer. That is the point of it. Gal Weizman, a researcher at Forever Security, spent his time on a simpler question: can somebody else borrow those rights without asking you?

The answer he published is called BragJack. One malicious browser extension was demonstrated against five targets — Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon and Anthropic's Claude in Chrome. The five vendors paid out more than $20,000 in bug bounties, from $600 to $7,000, and two CVEs came out of it. The catch: the extension has to already be installed. Once it is, Weizman shows the abuse can run with no clicking from the victim at all. Google and Microsoft have since resolved the flaws they were assigned.

What it means

Weizman describes these assistants as having two halves. The AI model decides what should happen. A separate, privileged part of the browser actually does it — opening tabs, reading content, taking screenshots, touching websites. The trick is that the doing half trusts the deciding half. An extension does not have to break the assistant. It only has to get into the conversation and start giving orders.

He calls the technique Prompt Forcing. Ordinary prompt injection hides instructions inside a page and hopes the AI reads them. Prompt Forcing hands the agent an entire prompt and the follow-up steps, and the agent converts them into perfectly legitimate browser actions with privileges it already has. In the Comet demo that meant opening Perplexity, summarizing the victim's emails and sending the results to another address.

Nothing in that chain looks like a virus. The program reading your mail is the one you installed on purpose, doing exactly what you allowed it to do. The only thing that changed is who is dictating the instructions — and that, as the researcher points out, is awkward for security software that is trained to spot bad code.
Share this

It also lands on top of a pattern. The reporter of this story says he had earlier flagged Claude for Chrome running its built-in AI workflows on synthetic clicks without checking they came from a real person, and that the flagged code was still reproducible eight releases later. Before that came ClaudeBleed, a flaw in the same extension disclosed by LayerX in April. Capability is shipping faster than the checks around it.

Who it matters to

Anyone who collects extensions the way other people collect apps: the student with a coupon finder, a screenshot tool and three AI helpers installed during exam week; the freelancer whose whole workflow lives in the browser and who clicked through a permission box asking to read and change all your data on all websites. And anyone who turned on the browser's AI assistant because it summarizes things nicely, without ever asking what else it is allowed to touch. In Chrome's case the researcher says the access could reach local files, web content, screenshots and potentially the camera and microphone.

What's next

Google and Microsoft have resolved what they were assigned — CVE-2026-0628 for Chrome, which carried a $7,000 bounty, and CVE-2026-55945 for the Edge race condition. About Perplexity Comet, Opera Neon and Claude in Chrome the report says only that similar flaws were demonstrated; whether and when they are fixed, it does not say. No timelines were given. Weizman has published a full technical breakdown covering all five attacks, so the next signal is whether the other three vendors respond to it in public.

One detail to hold on to

Two vendors patched. The number that sticks is a different one: code flagged as unsafe and still reproducible eight releases later. Every browser is racing to give its AI more hands. The question nobody has answered is who else gets to hold them.

Sources: Bleeping Computer, September 19, 2026 — report by Ax Sharma on Gal Weizman's BragJack disclosure

Why we ran this7/10

Браузерные ИИ-помощники получили право читать файлы, почту и делать скриншоты — и исследователь показал, что одно вредное расширение превращает это право в готовый инструмент слежки сразу в пяти браузерах, включая Chrome, Edge и Comet.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← Loudoun County cut property taxes 30%. I…Next: The recruiter on your screen had someone e… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X