Dossier · Ongoing
Hijacked AI Browser Agents
From Zenity's PleaseFix in August to BragJack in September 2026: recurring hijackings of AI assistants built into browsers, tracked over time.
Browser AI assistants such as Gemini, Copilot, Claude, and Perplexity Comet separate a cloud-based “brain” from an executing “body” in the browser – and security researchers have repeatedly exploited exactly this interface since summer 2026. In August, Zenity used PleaseFix to show how five browser assistants can be remotely controlled via email or calendar invite, with no user click required.
In September, Forever Security followed up with BragJack: this time, a single malicious browser extension is enough to hijack the same five assistants. Both findings exploit the same structural weakness – browser extensions and websites get blanket access to the communication between the AI agent and its cloud service – so further variants are likely until vendors change the underlying architecture.