BragJack: One Extension, Five Agentic Browsers, No Prompt Injection Required

September 17, 2026 · SPR{K}3 Research

Install any extension. It doesn't need permissions on claude.ai or perplexity.ai or gemini.google.com. It just needs to be running. Once it is, it can reach into the AI assistant that ships with your browser and tell it to act as you — read your local files, list the sites you've visited, take screenshots, on some products turn on the camera and microphone. The AI doesn't refuse. There was nothing for the guardrail to catch. The extension didn't smuggle a prompt in. It walked through the door the browser left open between the extension layer and the privileged agent layer.

That is BragJack, disclosed this week by Forever Security researcher Gal Weizman. Five browsers are affected: Google Chrome with Gemini, Microsoft Edge in agentic mode, Opera Neon, Perplexity Comet, and the Claude in Chrome extension. All five have shipped patches. Google issued CVE-2026-0628; Microsoft issued CVE-2026-55945. Bounty payments totalled about $20,000 across Anthropic, Perplexity, Google, Microsoft, and Opera per OffSeq's Threat Radar summary.

What the extension gets

Per the Dark Reading writeup and PrivacyNeedle's summary, the reach differs by product:

The important detail is what the attack does not need. Forever Security's report is explicit that BragJack is not a prompt-injection attack, and does not rely on bypassing model alignment guardrails. Nothing in the AI's safety training is being defeated. The AI runs the extension's request because the runtime handed it to the AI as if it were the user's request.

Why five vendors shipped the same bug

This is a recurring pattern. In July, Manifold Security disclosed ClaudeBleed Reopened: an extension could dispatch a synthetic click and Claude for Chrome would run the corresponding privileged workflow because it never checked Event.isTrusted. Same class. Different vendor. Same day the bug shipped, the doorway was open.

In September the class extended to the server side too. The MervinPraison PraisonAI cluster, disclosed a day before BragJack, included CVE-2026-57124 — the PraisonAI UI accepts a caller-controlled command and hands it to StdioMCPClient to spawn a local process. Different substrate (server MCP versus browser extension), same shape: an unauthenticated peer on the same box, or the same browser, gets to run against the agent's authority.

Every AI vendor now shipping an in-browser agent has to answer the same question the browsers have never fully answered for extensions themselves: how does the runtime tell an intended request from a scripted one that arrived by way of an installed extension? Five products got the same answer wrong this year on the browser side. Server MCP runtimes are getting it wrong on the network side. The class predates AI, but AI-agent authority envelopes make each individual mistake much more consequential.

Where the check has to live

The five vendors patched their side. Weizman's proof of concept is not observed in the wild yet, per The Hacker News coverage. Those are the good outcomes and they are the outcomes that reliably happen with named research — a researcher finds a class, five vendors ship fixes, bounties get paid. The class then re-appears at the next vendor.

The question the class raises is the one that survives any individual patch: when the browser or the server runtime hands the agent an action, what does the agent trust the caller with? A per-vendor answer written into a per-vendor click handler or per-vendor auth middleware works until the next vendor. An answer written outside the agent — one that watches what the process actually does, compares it to what the user actually asked for, and treats a camera flip or a filesystem read as an event that needs to look like something the user did, not just something the runtime dispatched — is the layer that survives another five vendors shipping the same failure. That layer is the one BragJack, ClaudeBleed Reopened, and the PraisonAI MCP-connect CVE all land on.

Sources


SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.