ARTICLE AD BOX
AI assistants are moving deeper into the browsers we use every day. They can summarize a webpage, explain what you are looking at and, in some cases, take action on websites for you. That convenience also gives these tools access that a normal webpage would never have. Now, security researcher Gal Weizman of Forever Security has shown how a malicious browser extension could potentially turn those powerful AI capabilities against you. His research, called BragJack, targeted Gemini Live in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon and Anthropic's Claude in Chrome. The findings resulted in more than $20,000 in bug bounties and two CVEs.
There is one important detail before you panic. The attack still required the malicious extension to be installed first. After that, Weizman demonstrated attacks that needed zero additional clicks from the victim. So how could one extension get that far inside the browser? It comes down to how these AI assistants are built.
Missed CyberGuy LIVE? Watch the replay and discover 5 ways AI can help you get better healthcare.
Our free CyberGuy LIVE class, Get Better Healthcare With AI, has ended, but you can still watch the full replay. Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed.
Watch the free replay + downloadable checklist now at CyberGuyLive.com
AI MALWARE CAN REWRITE ITSELF TO EVADE DETECTION
Weizman describes these AI systems as having a "brain" and a "body." The AI model works out what should happen. A privileged component inside the browser then carries out the request. Depending on the product, that privileged component might read webpage content, capture a screenshot or interact with a website. That setup becomes risky if something else inside the browser can manipulate the connection between those pieces. The proof-of-concept attacks relied heavily on Chromium's declarativeNetRequest, or DNR, system. Browser extensions can use DNR to modify how network requests work. That can include changing response headers or redirecting resources. Forever Security showed how those capabilities could let an extension interfere with web content trusted by a browser's AI features.
Chrome was one of the more striking examples. Google's Gemini side panel essentially has two pieces. Gemini handles the intelligence behind the request while Chrome provides the browser-level abilities needed to carry it out. Researchers found that Chrome already prevented extensions from directly injecting scripts into the Gemini page. However, the researchers discovered that an extension could still manipulate certain network requests used inside the Gemini experience. That gap allowed Weizman to demonstrate access to browser capabilities that the extension itself should never have received. According to the research, he could access local files, capture screenshots and obtain browser profile information. The researcher says the flaw also let him turn on the camera and microphone with zero clicks from the user. Google awarded the researchers a $7,000 bounty for reporting the vulnerability, which received the identifier CVE-2026-0628.
Google has since confirmed to CyberGuy that it has closed this specific attack path. A Google spokesperson told us, "Confirming we've released a patch in Chrome so this method no longer works on the Gemini side panel." That means the technique demonstrated by the researchers should no longer work against the Gemini side panel in an updated version of Chrome.
Perplexity Comet raised a different concern because its AI agent can take actions inside websites. Weizman found that Comet's built-in agent trusted several Perplexity domains. One testing domain lacked the same extension protections used on the main Perplexity site. Normally, that testing address redirected elsewhere. The proof-of-concept used DNR to remove the redirect and load the page instead. That gave the extension a path to communicate with Comet's built-in agent. The demonstrated access included browsing history, screenshots and local files. Then things became more personal. Weizman demonstrated sending an instruction that told the agent to access Perplexity, summarize the victim's recent emails and send the information to another email address. The AI agent performed the browser actions using capabilities it already had.
Microsoft built safeguards into Edge to keep outside prompts from easily controlling what its AI agent could do. Researchers still found a way around them. Weizman discovered a timing flaw known as a race condition. In simple terms, his test extension could feed the AI a prompt and then quickly switch on its ability to take action before Edge finished checking whether the request should be allowed. That opened the door for the AI agent to carry out a command it should not have accepted. Microsoft tracked the flaw as CVE-2026-55945 and rated it medium severity. The company says Edge versions before 150.0.4078.48 were affected. Updating Edge closes this particular security hole.
Forever Security also demonstrated related attacks against Opera Neon and Claude in Chrome. There is an important difference with Claude. Claude in Chrome is itself a browser extension, rather than a complete browser. The researcher found that a page on Claude's domain could send prompts to the extension's side panel. Another extension could manipulate that trusted page and force prompts into Claude. Forever Security says Anthropic awarded a bounty for the finding and classified it as medium severity. Opera Neon also allowed the proof-of-concept extension to reach its AI agent. According to the researcher, that access could force the agent to carry out instructions on websites. All five demonstrations were Chromium-based, which helped the researcher reuse the same basic attack approach.
We reached out to Google, Microsoft, Perplexity, Opera and Anthropic for comment on the research. Google responded with the update included above. Microsoft pointed us to its CVE-2026-55945 security advisory and said it had nothing further to share. We did not hear back from Perplexity, Opera or Anthropic before our deadline.
LOCK DOWN YOUR CHATGPT ACCOUNT BEFORE THE NEXT AI ATTACK
You may already have heard about prompt injection. That usually involves hiding malicious instructions in something an AI reads. Weizman calls this new approach Prompt Forcing. Here, the attacker does not need to hide instructions inside a webpage and hope the AI follows them. The attacker can force a complete prompt into the agent through a channel that the browser or assistant trusts. The AI can then turn that plain-English instruction into legitimate browser actions. That creates an interesting problem for security software. A suspicious program stealing an email may be easier to spot. An approved AI agent opening a website and clicking a button can look like normal browser activity. The published BragJack research describes proof-of-concept attacks and does not report that these techniques have been exploited in the wild. Still, the research shows how the security equation changes as AI agents receive deeper access to browsers and computers.
The attack starts with something many of us barely think about anymore: a browser extension. CyberGuy has covered malicious extensions that pretended to be AI assistants,hijacked online accounts and even turned trusted extensions into data-stealing spyware. That makes extension cleanup one of the easiest steps you can take right now. Maybe you installed a coupon extension two years ago and forgot about it. Perhaps you tested an AI sidebar once and never opened it again. If you no longer need an extension, there is little reason to keep giving it access to your browser.
Browsers receive security fixes regularly, so install updates as soon as they become available. Google's response makes that especially relevant here. The company says it has already released the Chrome patch that blocks the Gemini side-panel method demonstrated by the researchers. Restart Chrome after an update if prompted so the newest version can finish installing.
Open your browser's extension manager and remove anything you do not recognize or no longer use. Here is the quickest way to check:
Chrome and Claude in Chrome: Click the three-dot menu → Extensions → Manage extensions → find the extension → Remove. Google confirms this path in its current Chrome instructions.
Microsoft Edge: Click the Extensions puzzle-piece icon → Manage extensions → find the extension → Remove.
Opera Neon: Open the Extensions area from the browser sidebar or menu → review your installed extensions → remove anything you no longer trust or use. Opera documents its extensions manager through the Extensions icon and menu.
Perplexity Comet: Open the browser's extensions manager and review imported or installed Chrome extensions. Comet supports Chrome extensions and can import them from Chrome.
Pro tip: If you are unsure about an extension, disable it first and research the developer before removing it.
THOUSANDS OF HACKED SITES TRICK YOU INTO INSTALLING MALWARE
Look carefully when an extension asks for broad access to websites or browser activity. The permission should make sense for what the extension actually does.
Some browsers let you decide whether an extension can run on every website or only certain sites. Give an extension the narrowest access it needs to work.
An extension that uses a familiar AI name may have no connection to the company behind that AI service. Check the publisher before installing it.
If your browser gives you the option to disable an AI assistant or agent you never use, consider turning it off. That reduces the number of powerful browser features available if another component gets compromised.
Strong antivirus software can help flag malicious downloads and suspicious activity connected to bad extensions. It adds another layer of protection if something slips past you. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
Do not install one because it sounds useful for five minutes. Every extension adds code and permissions to the browser you use for email, banking, shopping and other private activity.
What gets my attention here is how much more powerful a bad browser extension can become when an AI agent enters the picture. We already knew extensions could spy on browsing or steal account data. This research shows a possible path to something with much broader privileges. There is also a practical takeaway. These demonstrations still required the attacker-controlled extension to get inside the browser first. Once it was there, however, the researcher showed that the attack could continue without another click from the victim. I would take five minutes and look through your extensions today. If you cannot remember why you installed one, find out what it does. If you stopped using it months ago, remove it. As browser AI grows more capable, the companies building these tools also need strong barriers between ordinary extensions and the privileged systems that let AI act for us.
Would you still let an AI assistant control parts of your browser if a malicious extension could potentially turn that access against you? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report
Copyright 2026 CyberGuy.com. All rights reserved.

2 hours ago
3







English (US) ·