$ techbeacon▋
CVE & Exploits

Security Researchers Reveal Proof‑of‑Concept Attack That Hijacks Multiple AI Chatbots via a Single Malicious Browser Extension

Security Researchers Reveal Proof‑of‑Concept Attack That Hijacks Multiple AI Chatbots via a Single Malicious Browser Extension

A new proof‑of‑concept exploit, dubbed BragJack, demonstrates that a single malicious browser extension can commandeer a range of AI‑powered chat assistants, including those embedded in Chrome, Edge, Opera Neon, Perplexity Comet and Claude for Chrome. The technique, presented by security researcher Gal Weizman of Forever Security, leverages prompt‑forcing to redirect user queries to attacker‑controlled prompts, effectively turning the assistants into tools for the attacker.

The attack works by installing a seemingly innocuous extension that intercepts the data flow between the browser and the AI service. Once active, the extension injects specially crafted prompts that override the original user request, causing the AI to generate responses dictated by the attacker. Because the extension operates at the browser level, it can target multiple AI platforms that rely on the same underlying web interface.

BragJack’s demonstration earned more than $20,000 in bounty payments and resulted in two publicly disclosed CVE identifiers, underscoring the seriousness with which the security community views the threat. The CVEs highlight both the extension’s ability to manipulate prompt handling and the broader risk of supply‑chain attacks on browser extensions that gain elevated permissions.

Experts note that the rise of conversational agents integrated directly into browsers has expanded the attack surface for malicious actors. Unlike traditional web‑based exploits that require a user to visit a compromised site, a malicious extension can persist across browsing sessions and affect any AI service the user accesses. This persistence makes detection more challenging, as the extension may appear legitimate while silently altering AI outputs.

While BragJack remains a proof‑of‑concept, its existence raises concerns for both end users and organizations that rely on AI assistants for productivity tasks. Security best practices recommend scrutinizing extension permissions, limiting installations to trusted sources, and employing extension monitoring tools that can flag anomalous behavior. Browser vendors have been urged to tighten review processes for extensions that interact with AI APIs.

The disclosure also adds pressure on AI service providers to harden their prompt‑handling mechanisms. Some developers are already exploring server‑side validation of prompts and stricter authentication for API calls to mitigate the risk of external manipulation. As AI assistants become more embedded in everyday workflows, the interplay between browser security and AI integrity is likely to become a focal point for future research and policy development.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related