Browser extensions could seize control of five built-in AI assistants

Browser extensions could seize control of five built-in AI assistants. A proof-of-concept attack demonstrated that an ordinary browser extension could take control of a privileged AI assistant.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, September 17th, 2026.

A proof-of-concept attack demonstrated that an ordinary browser extension could take control of a privileged AI assistant. The BragJack research affected AI environments in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome. The attack crossed a boundary between untrusted extensions and highly privileged agents, enabling access to sensitive information and potentially destructive actions. The affected companies acknowledged individual weaknesses, paid bug bounties and resolved the reported issues.

This is important because agentic browsers can act on authenticated websites, local files and connected devices. That gives a compromised extension more reach than traditional browser abuse. The researchers also said the attack didn’t depend on prompt injection or bypassing an AI guardrail.

Leaders should require a formal risk assessment before deploying browser AI broadly. Defenders should update Chromium-based browsers, remove extensions that haven’t been vetted and examine suspicious interactions involving browser agents. AI assistants create new trust boundaries when they combine browser access with authority to take action. Update affected browsers and allow only vetted extensions on devices where built-in AI agents are enabled.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Browser extensions could seize control of five built-in AI assistants
Broadcast by