A new proof-of-concept attack, dubbed BragJack, has been discovered that can compromise five agentic browser environments and steal sensitive information, as reported by Dark Reading.The BragJack attack, detailed by researcher Gal Weizman of Forever Security, targets Google Chrome with Gemini, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. Unlike previous AI attacks, BragJack does not rely on prompt injection or bypassing AI guardrails. Instead, it exploits a shared architectural flaw in how these agentic browsers interact with extensions, allowing attackers to hijack communication channels and force the AI agent to execute commands.This vulnerability affected hundreds of millions of users who had extensions installed. Google and Microsoft have issued CVEs for the flaws in their respective browsers, and all identified vulnerabilities have since been resolved. Organizations are advised to keep browsers updated, remove unvetted extensions, and implement enhanced monitoring within security operations centers to detect suspicious AI agent behavior.Source: Dark Reading
AI/ML
New BragJack attack compromises 5 agentic browsers
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
