CVE Tools
Back to feed
PoC public Chrome ai-ml Edge Google Chrome web-app

BragJack Attack Can Turn a Browser's Agentic AI Against It

Dark Reading·By Elizabeth Montalbano··5 min read
CVE Tools coverage

Researchers released the BragJack proof of concept, showing how malicious browser extensions could seize control of built-in AI agents in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. The flaws, including CVE-2026-0628 in Chrome and CVE-2026-55945 in Edge, could enable access to sensitive data and actions on authenticated websites; the affected vendors have addressed the reported issues.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store