← Founder Notes
Archive

Forever security showed one ordinary browser extension could hijack the built-in ai in five…

Yethikrishna ROriginal on Threads

forever security showed one ordinary browser extension could hijack the built-in ai in five chromium products — gemini live, perplexity comet, edge, opera neon, claude in chrome — and drive the agent to act for the attacker. the extension had no special powers, just the permissions any ad blocker asks for.

browser agents inherit every weakness of the extension model.

Context

Forever Security's write-up of 16 September 2026, BragJack, says one extension hijacked the agents inside Gemini Live in Chrome, Microsoft Edge, Opera Neon, Perplexity Comet and Claude in Chrome. The mechanism is that extensions can inject content scripts into websites, including pages that control the browser's AI. For Claude the script runs on Anthropic's own domain and can send messages to the assistant, and for Edge the browser creates a permission for Microsoft's marketing page. A table lists bounties: Chrome 7,000, Comet 7,000, Edge 5,000, Neon 900 and Claude in Chrome 600 dollars.

How it compares

This is a researcher demonstration under per-browser conditions, described in the researcher's own write-up. Bounties suggest vendors accepted reports, but per-vendor patch status and the tested versions were not found in the text read, so this is not a statement that the flaw is current or fixed. No special powers is the researcher's framing, and the exact extension permissions were not itemized. The closing line is the author's opinion.

Related work

Watch next

  • Per-vendor patch status.

Sources

  1. BragJack (Forever Security, 16 Sep 2026)forever.security

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 18 September 2026 at 16:19 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/forever-security-showed-one-ordinary-browser-extension-could-DdbQlloCJ3X" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Forever security showed one ordinary browser extension could hijack the built-in ai in five…"></iframe>

More notes