CuraSec

Plan active

BragJack PoC hijacks AI browser agents via malicious extensions

2026-09-20 14:41 UTC · BleepingComputer · read the source ↗ #ai-agents#browser-security#supply-chain
  • Engineer — Learn: Novel PoC technique shows how a malicious browser extension can subvert AI agent behavior through prompt injection — no active exploitation, but engineers building AI browser integrations should review extension permission boundaries and agent trust models now.
  • SOC/IR — Learn: No IOCs, no active campaigns, and no mapped TTPs yet; file the malicious-extension-as-AI-hijack vector for future detection engineering as AI browser agents proliferate in enterprise estates.
  • Leader — Plan: Two CVEs and a $20K bounty signal vendors take this seriously — assess whether any enterprise AI browser tooling (Perplexity Comet, Claude in Chrome, Edge Copilot) is deployed in the environment and add browser-agent risk to the AI governance policy review this quarter.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.