Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

A Malicious Browser Extension Can Now Hijack Your AI Assistant

A security researcher just showed how one rogue browser extension can hijack the AI assistant living in your browser, from Copilot to Claude to Perplexity's Comet, reading your files and even sending your data out under your own name.

On 19 September, researcher Gal Weizman of Forever Security disclosed an attack called BragJack. A malicious extension manipulates the browser's traffic rules to reach the AI assistant's trusted, privileged core, bypassing the usual checks. Weizman demonstrated it against Chrome's Gemini, Edge, Perplexity Comet, Opera Neon and Claude in Chrome, forcing the assistant to read files and history and send emails the user never chose. It's proof-of-concept for now, not yet seen in the wild, but simple enough that it won't stay that way for long.

For any Sydney business using an AI browser assistant for real work, this is worth five minutes today. In the audits we run onboarding new clients across the Northern Beaches and wider Sydney, browser extensions are consistently the messiest part of the setup: old tools nobody remembers installing, still holding broad "read and change all data" permissions. That's exactly what BragJack abuses. Remove anything you don't recognise, and ask your IT provider to fold extension audits into your regular security reviews.

Written by Caleb Attard, Head of Business Operations, All IT Services. All IT is a Sydney-based managed IT provider supporting hospitality, not-for-profit and wealth management businesses across Australia.


Frequently Asked Questions

BragJack is a September 2026 proof-of-concept attack where a malicious extension hijacks a browser's AI assistant, letting it read files and browsing history and send emails without the user knowing.
Researchers demonstrated it against Chrome's Gemini, Microsoft Edge, Perplexity Comet, Opera Neon and Claude in Chrome. Other Chromium-based browsers with built-in AI features could be vulnerable too.
No, it's a research disclosure rather than an active exploit. The technique is simple enough to replicate that businesses shouldn't wait for a real incident before acting.
Review every browser extension in use, remove anything unused or unrecognised, and be cautious granting full-site access, especially on machines running an AI browser assistant.

Not sure what's quietly running in your team's browsers?

All IT can run an extension and access audit across your business as part of a wider security review, so nothing's watching more than it should be.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →