BragJack hijacks browser AI agents with no user interaction
Assessment
It is accurate that, once the attack is set up, BragJack runs without further user interaction and can control the AI agent to read data or act on the victim's behalf. But the load-bearing precondition is that a malicious extension must already be installed in the victim's browser, with the broad host permissions such extensions request — the technique does not run remotely, drive-by, or against a clean browser. BragJack is a disclosed proof-of-concept with no reported in-the-wild exploitation, and the vendor bounties ($600 to $7,000) reflect modest per-vendor severity ratings rather than a mass-compromise event. A reader who takes 'hijacks AI agents with no user interaction' to mean a remote or zero-touch attack would overstate the real-world risk, which is bounded by the need to first get a malicious extension installed.
Where this claim appeared
BleepingComputer · 2026-09-19
https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/What “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
BragJack: a malicious extension hijacks the AI agents in Chrome, Edge, Comet, Opera Neon and Claude in ChromeThink this assessment is wrong? Report an error.