A Malicious Browser Extension Can Now Hijack Your AI Assistant
A security researcher just showed how one rogue browser extension can hijack the AI assistant living in your browser, from Copilot to Claude to Perplexity's Comet, reading your files and even sending your data out under your own name.
On 19 September, researcher Gal Weizman of Forever Security disclosed an attack called BragJack. A malicious extension manipulates the browser's traffic rules to reach the AI assistant's trusted, privileged core, bypassing the usual checks. Weizman demonstrated it against Chrome's Gemini, Edge, Perplexity Comet, Opera Neon and Claude in Chrome, forcing the assistant to read files and history and send emails the user never chose. It's proof-of-concept for now, not yet seen in the wild, but simple enough that it won't stay that way for long.
For any Sydney business using an AI browser assistant for real work, this is worth five minutes today. In the audits we run onboarding new clients across the Northern Beaches and wider Sydney, browser extensions are consistently the messiest part of the setup: old tools nobody remembers installing, still holding broad "read and change all data" permissions. That's exactly what BragJack abuses. Remove anything you don't recognise, and ask your IT provider to fold extension audits into your regular security reviews.
Written by Caleb Attard, Head of Business Operations, All IT Services. All IT is a Sydney-based managed IT provider supporting hospitality, not-for-profit and wealth management businesses across Australia.
Frequently Asked Questions
Not sure what's quietly running in your team's browsers?
All IT can run an extension and access audit across your business as part of a wider security review, so nothing's watching more than it should be.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
