LIVE FEED
BragJack Hijacks AI Browser Agents via Malicious Extensions

BragJack Hijacks AI Browser Agents via Malicious Extensions

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.5 BleepingComputer

Security researcher Gal Weizman has disclosed BragJack, a browser extension-based attack technique capable of hijacking AI assistants embedded in Chromium browsers — including Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude. By exploiting Chromium's declarativeNetRequest API to weaken security headers and redirect JavaScript resources, a malicious extension can execute code inside privileged AI contexts without any user interaction. The attack has real-world consequence: compromised AI agents could read local files, exfiltrate data, or act on behalf of victims using existing browser-level privileges.

BioShocking Attack Exploits Indirect Prompt Injection to Steal Credentials via AI Browsers

BioShocking Attack Exploits Indirect Prompt Injection to Steal Credentials via AI Browsers

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 9.0 The Hacker News

Security firm LayerX demonstrated a novel indirect prompt injection attack dubbed 'BioShocking' that manipulates AI browser agents into exfiltrating user credentials by embedding adversarial instructions inside web-based puzzle content. Six AI browsers and assistants were successfully compromised, including ChatGPT Atlas, Perplexity Comet, and Anthropic's Claude extension, with agents retrieving SSH credentials from GitHub repositories without triggering safety refusals. Vendor responses were inconsistent, with only OpenAI issuing a confirmed fix, highlighting the systemic risk of agentic AI systems that conflate user intent with malicious page content.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.