Security & AI news

Browser AI agent security · By FireAI Security & Research Team · Published

Research shows a single rogue extension can hijack five browsers’ built-in AI agents

Research called BragJack shows one rogue extension can hijack AI agents in Chrome, Edge and other browsers. How to audit Safari and Chrome extensions on a Mac.

An AI agent icon and the FireAI mascot holding a block sign, next to the words “One rogue extension hijacks browser AI.”

A single browser extension, installed like any other, can seize control of the AI agent built into Chrome, Edge or several other browsers and make it act on an attacker's behalf, Fox News reported on 28 September 2026, drawing on research from the security firm Forever Security [1]. Researcher Gal Weizman calls the technique BragJack [2].

Background

A growing number of browsers now ship an AI agent that can read a page, take a screenshot, or carry out an action on a person's behalf, and that agent typically runs inside internal, trusted pages the browser itself treats as fully privileged. Browser extensions, by contrast, are third-party code that many people install for ad blocking, price comparison or similar tasks, and are granted permissions separately from that trusted layer [2].

Findings

According to Forever Security's own report, the technique starts with a permission many legitimate extensions already request: Chromium's declarativeNetRequest, meant for tools like ad blockers that rewrite web requests. Weizman found the same permission can weaken a page's security headers and redirect the JavaScript files it loads, including the internal pages a browser uses to communicate with its own built-in AI agent [2]. Rather than hiding an instruction inside a web page and hoping the AI reads it, the older "prompt injection" approach, the extension sends a complete, ready-made command directly down the trusted channel the browser vendor built for its own agent to receive orders on. The agent then carries out the instruction using whatever access it already has, including reading files, taking a screenshot, or, in one demonstration against Perplexity's Comet browser, summarising a user's recent emails and sending them to a specified inbox [2].

DiNneR Serving is the technique that abuses the combination of these two narratives to attack other browsers/extensions by injecting JS code into privileged contexts.

Gal Weizman, Forever Security, describing the underlying technique

Forever Security says it demonstrated the technique against Gemini Live in Chrome, Perplexity Comet, Microsoft Edge's Actions, Opera Neon and Claude in Chrome [2]. Google patched the Chrome/Gemini flaw, tracked as CVE-2026-0628, with a $7,000 bounty, and other vendors, including Anthropic, paid bounties for their own fixes [1]. The sources do not fully agree on where a second flaw, CVE-2026-55945, applies: Forever Security's report ties it to Perplexity Comet, while Fox News and BleepingComputer describe it as a race condition in Microsoft Edge [1] [3].

Implications for Mac users

The affected browsers, Chrome, Edge, Opera and browsers built on Chromium, all run on macOS, so a Mac with one of these browsers' AI features turned on is within the scope of this research. This is a proof of concept the vendors have already responded to with patches, not a confirmed active campaign [1] [2]. It points at a general weak spot: any extension with broad permissions sits in a position to interfere with what a browser's AI features can see and do, on any operating system that browser runs on.

Recommendations

  1. In Safari, go to Safari menu › Settings › Extensions, review every extension, and check whether its website access is set to All Websites, a specific list, or None.
  2. In Chrome, open chrome://extensions, check each extension’s Site access setting, and question anything set to On all sites.
  3. For any extension set to broad access, open its store listing and check the publisher name, last update date and recent reviews for signs of a rebrand or ownership change.
  4. Remove or disable any extension that is unrecognised, unused, or no longer needed.
  5. Install extensions only from the official Safari or Chrome Web Store, and read the requested permissions before installing rather than after something feels wrong.

Relevance to FireAI

FireAI is a network firewall that works at the level of an app, such as Safari or Google Chrome as a whole, not at the level of an individual extension inside that app. A malicious extension using the BragJack technique piggybacks on the browser’s own, already-permitted connections, so a firewall sitting outside the browser process cannot distinguish a request the browser made itself from one triggered by a rogue extension; the traffic looks identical on the network. FireAI cannot detect, list, disable or remove a browser extension, which is why the audit steps above matter.

  • The world map plots every destination Safari or Chrome talks to, by company and country, per app rather than per extension.
  • If a browser that normally reaches a handful of familiar services suddenly connects somewhere new, a connection prompt or a line on the map surfaces that, and Investigate a connection gives a risk score and the reasons behind it.
  • With per-app rules, a browser can be scoped to the destinations it actually needs, and security modes tighten that further on an untrusted network.

Limitations

None of the sources reports a confirmed case of BragJack used against a real victim outside Forever Security's own testing; the vendors involved had patched the reported flaws by the time coverage appeared [1] [2]. The sources disagree on which browser CVE-2026-55945 affects, which this piece flags rather than resolves [1] [3]. It is not established how many extensions in general use the declarativeNetRequest permission in a way that could be abused the same way.

FireAI is made by HisnLabs.

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. Fox News (Kurt Knutsson, CyberGuy), 28 September 2026: Malicious browser extensions can hijack AI assistants
  2. Forever Security (Gal Weizman), 16 September 2026: BragJack, the attack that hijacks every browser agent
  3. BleepingComputer (Ax Sharma), 19 September 2026: BragJack attacks hijack AI browser agents through malicious extensions