A single malicious browser extension can now seize control of the integrated AI assistants in Chrome, Edge, Opera, Perplexity Comet, and Claude, demonstrating a systemic flaw in the trust model browsers use to connect extensions with AI agents.
Security researcher Gal Weizman of Forever Security revealed the "BragJack" proof-of-concept, which exploits the privileged access granted to browser extensions to hijack their embedded AI features. The attack, which bypasses typical web-based prompt injection, used a "Prompt Forcing" technique to earn Weizman over $20,000 in bug bounties and prompted two separate CVE assignments.
The core issue is architectural. Browser extensions are granted deep permissions to interact with web content and browser functions, a model that was not designed with modern AI agent integration in mind. This creates a direct bridge for a malicious extension to intercept, modify, or commandeer the AI assistant, effectively turning it into an attacker-controlled tool acting with the user's full authority.
This elevates the threat posed by malicious extensions from data theft or adware to a system control problem. An attacker could use a hijacked AI agent to execute actions across tabs, access sensitive information, or perform fraudulent activities under the guise of the user's own trusted assistant.
The fact that BragJack succeeded across five major platforms confirms this is a common design challenge, not an isolated vendor bug. It underscores an urgent need for the industry to re-architect the isolation between extensions and AI services with stricter permission models and zero-trust principles.
In response, IT security teams must immediately adapt their extension policies. The traditional approach of allowing popular extensions is no longer sufficient. Immediate actions include:
- Enforcing Strict Extension Allowlists: Only permitting pre-vetted extensions that meet specific security criteria.
- Auditing Existing Extensions: Reviewing and removing any extensions with overly broad permissions or from untrusted developers.
- Governing AI Browser Features: Treating integrated AI assistants as privileged tools, requiring explicit governance for their use in corporate environments.
End-users should also apply greater scrutiny to browser extensions, treating them like installed software by granting minimal permissions, researching developer reputation, and regularly auditing their installations.
As browsers become platforms for autonomous AI agents, securing the extension ecosystem is paramount. The BragJack research highlights a critical expansion of the attack surface that requires a swift evolution in defensive strategies.
單一惡意瀏覽器擴充功能現可接管Chrome、Edge、Opera、Perplexity Comet及Claude內置的AI助理,揭示瀏覽器用於連接擴充功能與AI代理的信任模型存在系統性缺陷。
Forever Security的安全研究員Gal Weizman揭露名為「BragJack」的概念驗證攻擊,此手法利用賦予瀏覽器擴充功能的特權存取來劫持其嵌入的AI功能。該攻擊繞過常見的網頁提示注入,採用「強制提示」技術,為Weizman賺取逾2萬美元漏洞賞金,並促使兩個獨立CVE漏洞編號分配。
核心問題在於架構設計。瀏覽器擴充功能被賦予與網頁內容及瀏覽器功能深度互動的權限,此模型並非為現今AI代理整合而設計。這為惡意擴充功能創造了直接橋樑,能攔截、篡改或奪取AI助理控制權,實質將其轉化為攻擊者控制的工具,並以用戶完整權限執行操作。
此舉將惡意擴充功能的威脅層級從數據竊取或廣告軟件提升至系統控制問題。攻擊者可利用被劫持的AI代理跨分頁執行操作、存取敏感資訊,或以用戶可信助理身份進行欺詐活動。
BragJack成功橫跨五大平台的事實,證實此為普遍設計缺陷而非單一廠商漏洞。這突顯業界須以更嚴格權限模型及零信任原則,重新架構擴充功能與AI服務間的隔離機制。
因應此威脅,IT安全團隊必須立即調整擴充功能政策。僅允許熱門擴充功能的傳統做法已不再足夠。應即時採取以下措施:
- 強制執行嚴格擴充功能白名單:僅允許通過預先安全審核且符合特定標準的擴充功能。
- 審計現有擴充功能:審查並移除任何權限過廣或來自不受信任開發者的擴充功能。
- 規管AI瀏覽器功能:將內置AI助理視為特權工具,在企業環境中使用時須建立明確治理機制。
終端用戶亦應對瀏覽器擴充功能提高警覺,將其視為已安裝軟件對待,僅授予最低必要權限,查證開發者信譽,並定期審核安裝內容。
隨著瀏覽器成為自主AI代理平台,確保擴充功能生態系統安全至關重要。BragJack研究突顯攻擊面臨的關鍵性擴展,需防禦策略快速演進以應對。
