A newly demonstrated attack reveals how a single malicious browser extension can seize control of the AI assistants built into major web browsers, weaponizing them to steal user data and execute commands without consent.
Security researcher Gal Weizman of Forever Security has published a proof-of-concept called BragJack, which exploits a technique he terms "Prompt Forcing." The attack successfully hijacks the AI capabilities integrated into Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and the Claude assistant within Chrome.
The core vulnerability lies in the privileged relationship between browser extensions and the AI models they access. A malicious extension uses its permissions to inject hidden instructions directly into the AI agent's workflow. Operating within the agent's trusted environment, these forced prompts bypass standard security controls, enabling tasks like exfiltrating credentials or personal information.
This is not a theoretical flaw. The severity of BragJack has been independently validated, earning Weizman over $20,000 in bug bounties and resulting in the assignment of two distinct CVE identifiers. The substantial payouts and formal tracking confirm the issue represents a critical weakness in current AI-integrated browser designs.
The attack dramatically expands the modern browser's attack surface. As browsers evolve into proactive, AI-powered assistants, they merge the deep system access already granted to extensions with the potent instruction-following abilities of large language models. BragJack demonstrates that this combination creates a prime target for exploitation, accessible through just one malicious plugin.
The findings demand a dual response. For browser developers and platform vendors, it underscores an urgent need to re-architect security models. Current permission frameworks are often too broad; future protections must incorporate stricter sandboxing, granular controls, and new verification steps specifically governing AI interactions.
For users, the lesson is one of heightened vigilance. The research starkly illustrates that browser extensions now carry greater risk. Users must be extremely selective, installing only from trusted developers and carefully scrutinizing every permission request. With AI assistants becoming standard, a malicious extension's potential harm has escalated from passive data collection to active command execution.
BragJack serves as a critical warning. The convenience of embedded AI agents brings sophisticated new threats that both the industry and end-users must proactively confront.
一項新展示的攻擊揭示了單一惡意瀏覽器擴充功能如何能奪取對主流網絡瀏覽器內置 AI 助手的控制權,將其武器化以在未經同意的情況下竊取用戶數據並執行指令。
安全研究人員 Gal Weizman(來自 Forever Security)發表了一個名為 BragJack 的概念驗證,他利用了一種稱為「強制提示」的技術。此攻擊成功劫持了整合在 Google Chrome、Microsoft Edge、Opera Neon、Perplexity Comet 及 Chrome 中 Claude 助手的 AI 功能。
核心漏洞在於瀏覽器擴充功能與其訪問的 AI 模型之間的特權關係。惡意擴充功能利用其權限,將隱藏指令直接注入到 AI 代理的工作流程中。這些強制提示在代理的可信環境中運作,繞過了標準安全控制,從而實現了諸如竊取憑證或個人資訊等任務。
這並非理論缺陷。BragJack 的嚴重性已獲獨立驗證,為 Weizman 贏得了超過 2 萬美元的漏洞賞金,並獲分配了兩個不同的 CVE 標識符。豐厚的獎金和正式的跟蹤確認了此問題代表了當前 AI 整合瀏覽器設計中的一個關鍵弱點。
該攻擊大幅擴展了現代瀏覽器的攻擊面。隨著瀏覽器發展為主動式、AI 驅動的助手,它們將已賦予擴充功能的深度系統訪問權限與大型語言模型強大的指令遵循能力相結合。BragJack 證明,這種組合創造了一個易於利用的首要目標,僅需一個惡意插件即可達成。
研究結果要求雙重回應。對於瀏覽器開發者和平台供應商而言,它強調了重新設計安全模型的迫切需求。現有的權限框架往往過於寬泛;未來的保護措施必須納入更嚴格的沙盒機制、更細緻的控制,以及專門規範 AI 互動的新驗證步驟。
對於用戶而言,教訓是需要更高的警覺性。研究清楚地表明,瀏覽器擴充功能現在帶來更大的風險。用戶必須極度謹慎選擇,僅從可信開發者處安裝,並仔細審視每一個權限請求。隨著 AI 助手成為標準配置,一個惡意擴充功能的潛在危害已從被動的數據收集升級為主動的指令執行。
BragJack 是一個重要的警示。內置 AI 代理帶來的便利性,伴隨著複雜的新威脅,業界和最終用戶必須主動應對。
