[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8czbS7LqI36-LEMnlMNzFyvB93ZQNJ0SbRvU3W_7Mkc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"e9c0bdc7-f967-4d9b-9325-db70742385ce","malicious-browser-extensions-can-hijack-ai-agents-via-bragjack-attack","b2eb5282-3c55-4e04-801e-4aba97506a3a","Malicious Browser Extensions Can Hijack AI Agents via BragJack Attack","The BragJack attack demonstrates how a single malicious browser extension can exploit the declarativeNetRequest (DNR) API to intercept and manipulate network requests made by AI browser agents, effectively hijacking them to act on a user's behalf without their knowledge. The root issue lies in the over-privileged trust model granted to browser extensions and insufficient sandboxing between extensions and AI agent contexts. This matters because AI agents increasingly have access to sensitive data, authenticated sessions, and the ability to take real-world actions — making them high-value targets. As AI-native browser features proliferate, the attack surface expands dramatically if extensions are not subject to rigorous scrutiny and least-privilege controls.","**Immediate actions:**\n- Audit and remove all non-essential or unvetted browser extensions from enterprise and personal devices used for AI-assisted workflows.\n- Apply any browser vendor patches addressing the disclosed CVEs in Chrome, Edge, and Opera Neon immediately.\n\n**Access & configuration controls:**\n- Enforce extension allowlisting policies via enterprise browser management (e.g., Chrome Enterprise, Edge Group Policy) to block unauthorized extensions.\n- Restrict AI agent browser permissions to the minimum required scope and disable access to sensitive APIs where not strictly necessary.\n- Configure browsers to run AI agent sessions in isolated profiles or containers separated from general browsing contexts.\n\n**Detection & long-term improvements:**\n- Implement browser activity monitoring to detect anomalous network request interception or unexpected screenshot\u002Fautomation behavior by extensions.\n- Establish a formal vetting and approval process for any third-party browser extensions before they are permitted in the organization.\n- Educate users and developers on the risks of installing unverified extensions, particularly in environments where AI agents operate with elevated privileges.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Controlled Use of Administrative Privileges","CIS Control 9: Limitation and Control of Network Ports, Protocols, and Services","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 SC-39: Process Isolation","GDPR Article 32: Security of Processing (protecting personal data accessed by AI agents)","MITRE ATT&CK T1176: Browser Extensions","OWASP Top 10 LLM06: Sensitive Information Disclosure","published","2026-09-19T18:20:19.543361+00:00","2026-09-19T18:20:19.36+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fbragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions\u002F","bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions-fb9113","BragJack attacks hijack AI browser agents through malicious extensions",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"4750d5e8-be58-4807-aa15-baab6990c46c","2026-09-20","morning","ThreatNoir Weekend Brief — September 20","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-20\u002Fthreatnoir-morning-brief-2026-09-20.mp3"]