Malicious Extensions Exploit AI Browser Agents Security researcher Gal Weizman has demonstrated a proof-of-concept called BragJack that lets a single malicious browser extension hand instructions to AI-powered browser agents in Chromium-based browsers, allowing the agent to act with the browser's existing privileges and putting a user's entire online presence at risk. The vulnerability hijacks AI assistants embedded in those browsers. Imagine a single malicious browser extension handing an AI-powered browser agent a set of instructions, allowing it to act with the browser's existing privileges - and putting your entire online presence at risk. Security researcher Gal Weizman has uncovered this vulnerability with his proof-of-concept, BragJack, which can hijack AI assistants embedded in popular Chromium-based browsers.