Browser extensions could seize control of five built-in AI assistants
Daily Cyber News: Browser extensions could seize control of five built-in AI assistants
A proof-of-concept attack demonstrated that an ordinary browser extension could take control of a privileged AI assistant. The BragJack research affected AI environments in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome. The attack crossed a boundary between untrusted extensions and highly privileged agents, enabling access to sensitive information and potentially destructive actions.
Key context: This is important because agentic browsers can act on authenticated websites, local files and connected devices.
Additional detail: Leaders should require a formal risk assessment before deploying browser AI broadly.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, Browser, extensions, seize, control, five, built-in, assistants.