Malicious browser extensions are getting closer to the most powerful tools inside modern browsers, and that is where the danger spikes fast. New research shows that once a shady extension is inside the browser, it may be able to push AI assistants into doing far more than a user expected, including reading content, grabbing screenshots and carrying out actions on websites.
Security researcher Gal Weizman of Forever Security tested this idea across Gemini Live in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon and Anthropic’s Claude in Chrome. The work, called BragJack, led to more than $20,000 in bug bounties and two CVEs, which is a strong sign that the problem is real even if the full attack still starts with one ugly requirement: the extension has to be installed first.
The core issue comes down to how browser AI features are built. Weizman describes them as having a “brain” and a “body,” where the model decides what should happen and a browser-level component carries out the request. That setup is useful, but it also creates a tempting target if an extension can meddle with the connection between the two pieces.
For the proof-of-concept attacks, the key trick was Chromium’s declarativeNetRequest system, or DNR. Extensions can use it to alter network traffic, which can mean changing headers or redirecting resources, and that can be enough to interfere with content an AI assistant trusts. It is a sharp reminder that browser permissions do not always stay neatly boxed in the way people assume.
Chrome’s Gemini side panel was one of the clearest examples. Google had already blocked extensions from directly injecting scripts into the Gemini page, but researchers found another route by manipulating certain network requests used in the experience. That opened the door to local file access, screenshots, browser profile information and, according to the research, even the camera and microphone with zero clicks from the user.
Google awarded a $7,000 bounty for that flaw, tracked as CVE-2026-0628, and later said the specific route had been patched. A Google spokesperson said, “Confirming we’ve released a patch in Chrome so this method no longer works on the Gemini side panel.” The fix matters, but it does not erase the bigger lesson about how much power these browser assistants can be given.
Perplexity Comet raised an even stranger concern because its agent can act inside websites. Weizman found that one trusted testing domain lacked the same protections as the main Perplexity site, and DNR helped remove a redirect so the page could load and talk to the built-in agent. From there, the demonstrated access included browsing history, screenshots and local files.
The Comet proof of concept also showed how personal this can get. The agent was instructed to visit Perplexity, summarize the victim’s recent emails and send the summary to another email address. Once the agent had the right browser access, it could carry out those steps in a way that looked like ordinary browser behavior, which is exactly what makes this class of attack so sneaky.
Microsoft Edge had its own weakness, even with safeguards in place. Researchers found a race condition that let a test extension feed the AI a prompt and then quickly switch on its action-taking ability before Edge finished checking whether the request should be allowed. Microsoft labeled the issue CVE-2026-55945 and said versions before 150.0.4078.48 were affected.
Opera Neon and Claude in Chrome were also shown to be vulnerable to related techniques. Claude in Chrome is itself a browser extension, and the research showed how a page on Claude’s domain could send prompts to its side panel, while another extension could manipulate that trusted page and force prompts into Claude. Anthropic classified the finding as medium severity and awarded a bounty.
The researcher calls the wider tactic Prompt Forcing, which sits alongside the more familiar idea of prompt injection. Instead of hiding instructions inside content and hoping the AI bites, the attacker can shove a complete prompt through a channel the assistant already trusts. That can make a malicious request look like a normal browser task, which is a problem for both detection tools and human intuition.
That is why browser extensions deserve a hard look, especially the ones installed and forgotten long ago. A coupon tool from years back, an AI sidebar tried once and never used again, or some shiny add-on with a familiar logo can all stay loaded with far more access than they need. If an extension is no longer useful, keeping it around just keeps the door cracked open.
Keeping the browser updated is another easy win, since vendors can and do patch these holes. It also helps to review extension permissions, limit access when possible and be skeptical of AI-branded add-ons that have no real connection to the company behind the name. The more powerful browsers become, the more important it is to keep the extras on a short leash.
