One Ordinary Extension Hijacked Chrome, Edge, and Claude AI Before Anyone Clicked a Thing
Forever Security's BragJack research, reported 16 September 2026, shows one Chromium extension can hijack built-in AI in Chrome, Edge, Comet, Opera Neon, and Claude. Chrome CVE-2026-0628 is CVSS 8.8, fixed in 143.0.7499.192. Edge CVE-2026-55945 is 4.2, fixed in 150.0.4078.48.

Forever Security researcher Gal Weizman published a demonstration branded BragJack. The Hacker News (Swati Khandelwal, 16 September 2026) reported that one ordinary Chromium extension could take control of built-in AI assistants in Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome. Dark Reading carried the same research.
This is a researcher demonstration. It is not exploitation observed in the wild, not a CISA Known Exploited Vulnerabilities listing for the full set, and not prompt injection. The earlier Chrome finding was named GlicJack.
The extension needed two common permissions: page modification of the kind ad blockers use, plus declarativeNetRequest. Together they let it seize the trusted page the built-in AI body listens to and send that body commands. The attack requires the malicious extension already installed and running. It is not a remote drive-by that works with no install.
Chrome is tracked as CVE-2026-0628, scored 8.8 by CISA, and fixed in Chrome 143.0.7499.192 in early January 2026. Capabilities there include reading local files, enabling the camera and microphone, and taking screenshots. Edge is CVE-2026-55945, scored 4.2, fixed in Edge 150.0.4078.48 on 2 July 2026, and can control the AI agent.
Comet, Opera Neon, and Claude in Chrome had no CVE yet in the reporting. Forever Security described Comet as the worst case: read files, browsing history, screenshots, and act as the user. The researchers said this is worse than prompt injection because the attacker can feed prompts directly through the hijacked trusted channel.
Forever Security said it earned about $20,000 in bug bounties across the five products. The per-product figures add up to $20,500 ($7,000 Chrome, $7,000 Comet, $5,000 Edge, $900 Opera, $600 Claude).
As of 16 September 2026, neither CVE was on the U.S. Known Exploited Vulnerabilities catalog, and The Hacker News said there was no public evidence of a real-world attack. Chrome and Edge have published fixed versions. For Comet, Opera Neon, and Claude in Chrome, Forever Security said each vendor paid a bounty, and The Hacker News said those three had no published fix date for the exact method. Dark Reading wrote that the issues have since been resolved.
Related browser and account-takeover tape includes the HBO Max Reddit ClickFix campaign, the All-in-One WP Migration takeover risk, and OpenAI rogue agents on Hugging Face.
Security teams should update Chrome to 143.0.7499.192 or later and Edge to 150.0.4078.48 or later this week, then remove any Chromium extension the organization did not vet that can rewrite pages or network requests.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free