What happened?
BleepingComputer reported an attack class named BragJack in which malicious browser extensions are used to hijack AI browser agents. The report was submitted to Hacker News on 20 September 2026.
Why people care
Browser agents are increasingly given real credentials and real sessions. If a browser extension can steer the agent, the attacker inherits whatever the agent was allowed to do — which is exactly the access model this new wave of harnesses is built around.
The security lesson
Browser agents combine model decisions with an already-authenticated browser session. An extension does not need to defeat the model directly if it can change the page, intercept the interaction or redirect the action around the agent’s original intent.
Who should care?
Anyone testing browser automation with real accounts, payment sessions or internal tools should treat extension permissions as part of the agent threat model. Browser isolation, least-privilege accounts and a review step before irreversible actions matter as much as the model’s prompt.
What to verify
Read the original report for the attack chain and affected assumptions. The important follow-up question for a deployment is where the browser agent gets its credentials, which extensions are allowed to run, and whether sensitive actions can be independently confirmed.
Related
- Casbin Gateway, which filters agent HTTP traffic
- Browser automation tools generally