Zero‑Click ‘BragJack’ Exploit Lets Malicious Extensions Seize Browser AI Assistants
Security researchers have uncovered a new zero‑click attack, dubbed BragJack, that allows a malicious browser extension to take control of built‑in AI assistants across several major browsers without any user interaction. The technique can target the AI features in Google Chrome, Microsoft Edge, Opera Neon, Perplexity’s Comet service and the Claude assistant when it runs inside Chrome.
The researchers explain that BragJack leverages the privileged APIs granted to extensions for interacting with a browser’s native AI modules. By injecting crafted messages through these APIs, a rogue extension can redirect queries, harvest responses and even alter the assistant’s output. Because the exploit requires no clicks, it can be activated simply by installing the compromised extension, which may appear innocuous or be bundled with other software.
Zero‑click attacks are especially worrisome because they bypass the usual user‑driven safeguards that rely on prompting for permission or confirming actions. In the case of BragJack, the malicious code operates silently in the background, making detection difficult for both users and conventional security tools that monitor only overt behaviors such as network traffic spikes or pop‑ups.
Industry analysts note that the rise of AI‑driven features in browsers has expanded the attack surface. Extensions that once only needed access to web pages now can interact directly with conversational agents, retrieve context from a user’s browsing history and manipulate the assistant’s responses. While the researchers have responsibly disclosed the findings to the affected vendors, they warn that remediation may require updates to extension permission models and tighter vetting of AI‑related APIs.
For users, the immediate recommendation is to audit installed extensions, remove any that are unfamiliar, and rely on official extension stores that enforce stricter review processes. Browser developers are expected to roll out patches that limit the scope of extension‑to‑AI communications and introduce additional prompts when extensions attempt to invoke AI services. As AI assistants become more embedded in everyday browsing, the BragJack discovery underscores the need for ongoing vigilance and a re‑evaluation of how third‑party code interacts with these powerful new tools.
Comments (0)
Be the first to comment.
Join the discussion