Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

BragJack Attack Hijacks AI Browser Assistants via Malicious Extensions (CVE‑2026‑0628, CVE‑2026‑0630)

A new attack technique called BragJack lets a malicious browser extension take control of AI assistants in Chromium‑based browsers, exposing local files and device sensors. The flaw underscores the importance of third‑party extension governance for audit readiness and control assurance.

LiveThreat™ Intelligence · 📅 September 20, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

BragJack Attack Hijacks AI Browser Assistants via Malicious Extensions (CVE‑2026‑0628, CVE‑2026‑0630)

What Happened — Security researcher Gal Weizman disclosed a proof‑of‑concept attack, dubbed BragJack, that lets a malicious browser extension hijack AI assistants built into Chromium‑based browsers. The technique works across Google Chrome’s Gemini Live, Microsoft Edge, Perplexity Comet, Opera Neon, and Anthropic’s Claude, and resulted in two CVEs (CVE‑2026‑0628 and CVE‑2026‑0630).

Why It Matters for Trust & Control Assurance

  • Demonstrates how a third‑party extension can bypass browser‑level isolation and command privileged AI components, a scenario continuous control‑assurance programs are designed to detect and evidence.
  • Highlights the need for rigorous third‑party software governance, extension whitelist policies, and real‑time monitoring of declarativeNetRequest (DNR) rules as audit‑ready evidence.
  • Directly maps to the control objective of managing and monitoring third‑party components to prevent unauthorized privilege escalation, satisfying many framework requirements simultaneously.

Who Is Affected

  • Technology vendors and SaaS providers that embed AI assistants in browsers.
  • Enterprises that allow employees to install browser extensions on corporate devices.
  • End‑users of Chromium‑based browsers with AI features.

Recommended Actions

  • Inventory all installed extensions and enforce a whitelist of approved add‑ons.
  • Apply the patches released by Google and Microsoft for the disclosed CVEs immediately.
  • Deploy continuous monitoring of extension‑related DNR rules and generate immutable logs for audit purposes.
  • Incorporate extension‑governance checks into your third‑party risk management workflow.

Source: BleepingComputer

Technical Notes

  • Attack vector: malicious extension already present in the browser, leveraging Chromium’s declarativeNetRequest to modify network requests, weaken security headers, and inject code into AI agent contexts.
  • Impact: ability to read local files, capture screenshots, and potentially access camera/microphone via the hijacked AI component.
  • CVEs: CVE‑2026‑0628 (Chrome) and CVE‑2026‑0630 (Edge/Opera).

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →