- Sources: primary, discussion
- Summary: The disclosure, which the publisher calls BragJack, describes an ordinary extension reaching the assistant built into Edge, Comet and Opera Neon through the page the browser trusts to command it, using only content-script and request-rewriting permissions an extension already holds, and needing no prompt injection and no user click, with a fifth case against Claude in Chrome that is an extension rather than a browser, which the post calls an extension exploiting an extension and much less of a security risk, which Anthropic rated medium severity, and which drew the smallest bounty at $600. The Chrome case is prior work rather than new, because the post states the author published it earlier in 2026 as GlicJack, and the impact table marks browser agent hijack as not achieved there, with the demonstrated result being code execution inside the assistant component with local file access, microphone and camera access, a profile leak and screenshots, at the joint-highest bounty of $7,000. The post lists the ids CVE-2026-0628 and CVE-2026-55945 in a table whose columns do not survive text extraction, so neither id can be assigned to a specific product from this source, and it names no affected version and no fixed version for any of the five.
- Why it matters: The extension-to-browser boundary fails here through the agent's own trusted input path rather than through the browser, so an extension's stated permissions no longer bound what it can make the assistant do.
- Follow-up: Track fixed versions from Google, Microsoft, Perplexity, Opera and Anthropic, and the per-browser assignment of CVE-2026-0628 and CVE-2026-55945.
send feedback on this story