One bad extension can take over your browser's AI assistant
Browser makers have spent the year bolting AI assistants into the browser itself, able to read your tabs, summarise your mail and click things on your behalf. A researcher has now shown what happens when a malicious extension turns up in the same browser.
Gal Weizman of Forever Security published the technique on 19 September under the name BragJack. One extension, with small per-browser tweaks, hijacked the assistants in Google Chrome, Microsoft Edge, Opera Neon, Perplexity's Comet and Claude in Chrome. It abuses a Chromium feature called declarativeNetRequest, which exists so extensions can block and redirect network requests, to get attacker code into the privileged place where the assistant runs. The next step Weizman calls Prompt Forcing, and it is nastier than the usual prompt injection: instead of hiding instructions in a page and hoping the AI reads them, the attacker hands the assistant an entire prompt and the assistant carries it out as though you had typed it. Reading local files, pulling browsing history, taking screenshots, mailing summaries of your inbox to a stranger, all demonstrated.
Google rated its share of the problem 8.8 out of 10 and tracks it as CVE-2026-0628. Microsoft's is CVE-2026-55945. Both have been fixed, the vendors paid out roughly $20,000 in bounties between them, and nobody has seen this used in a real attack. It also needs an extension on your machine first, which is the part you actually control.
So do the dull thing this week. Open your browser's extensions page, remove anything you do not recognise or have not used in months, and read the permission box when something new asks to "read and change all your data on all websites", because that is the access this attack runs on. Then make sure the browser itself is current. Tendvane's app-update check uses winget to flag browsers and other installed programs that have fallen behind their latest version.