One Malicious Extension Can Hijack Your AI Browser Agent

·
Listen to this article~5 min

A new attack called BragJack can hijack AI assistants in Chrome, Edge, and more using one malicious extension. Learn how Prompt Forcing works and how to protect yourself.

Imagine you're working in Chrome, and your AI assistant—the one that helps you summarize pages, fill forms, and automate tasks—suddenly starts taking orders from someone else. That's exactly what a new proof-of-concept attack called BragJack does. And it's not just Chrome. Edge, Opera Neon, Perplexity Comet, and even Claude in Chrome are all vulnerable. Security researcher Gal Weizman from Forever Security discovered this attack. He used a technique called Prompt Forcing to hijack AI agents through a single malicious browser extension. The result? Over $20,000 in bug bounties and two CVEs. Not bad for a proof of concept. ### What Is Prompt Forcing? Prompt Forcing is a clever trick. It manipulates the prompts that AI agents use to understand your commands. By injecting malicious instructions, an attacker can make the AI do things you never intended—like exfiltrating data, clicking buttons, or even making purchases. Think of it like this: your AI assistant is a helpful robot. Prompt Forcing is like slipping a note into its instruction manual that says, "Ignore your owner and follow my orders instead." The robot doesn't know any better. ### How BragJack Works BragJack exploits the way AI agents in browsers interact with extensions. When you install an extension, it can request permissions to read and modify page content. If that extension is malicious, it can inject prompts into the AI's context. The AI then treats those prompts as legitimate user requests. Here's the scary part: you don't need to visit a shady website. The attack works on any page where the AI is active. And because it's a browser extension, it can affect multiple AI assistants across different browsers. > "The line between helpful automation and dangerous hijacking is thinner than most people think," Weizman noted in his disclosure. "Users trust their AI assistants, and that trust is exactly what attackers exploit." ### Which Browsers Are Affected? The proof-of-concept targeted five popular browsers: - Google Chrome - Microsoft Edge - Opera Neon - Perplexity Comet - Claude in Chrome Each of these uses an AI agent that can be manipulated via Prompt Forcing. While the attack is currently a proof of concept, the underlying vulnerabilities are real and have been reported to the respective vendors. ### What This Means for Antidetect Browser Users If you're using antidetect browsers for privacy or multi-accounting, this attack is a wake-up call. Antidetect browsers often rely on extensions to manage fingerprints and automate tasks. A malicious extension could not only hijack your AI assistant but also compromise your entire browser profile. - Always vet extensions before installing them. Check reviews, permissions, and the developer's reputation. - Use a separate browser profile for sensitive tasks. Don't mix your banking with your browsing experiments. - Keep your browser and extensions updated. Vendors are quick to patch known vulnerabilities. ### The Bigger Picture AI browser agents are becoming more common. They promise convenience, but they also introduce new attack surfaces. BragJack shows that even a single extension can be a gateway to widespread compromise. As Weizman's work demonstrates, security research is crucial. The $20,000 in bounties and two CVEs are a testament to the importance of responsible disclosure. But for everyday users, the lesson is simple: trust your AI assistant, but verify its inputs. ### How to Protect Yourself - Limit the number of extensions you install. Less is more. - Review permissions carefully. If an extension asks for more than it needs, be suspicious. - Consider using a dedicated antidetect browser for high-risk activities. It can isolate threats and protect your main identity. - Stay informed. Follow security researchers and news outlets that cover browser security. BragJack might be a proof of concept, but it's a glimpse into the future of browser-based attacks. As AI becomes more integrated into our daily browsing, the stakes will only get higher. Don't wait until it's your assistant that gets hijacked.