Dossier · Ongoing

Hijacked AI Browser Agents

From Zenity's PleaseFix in August to BragJack in September 2026: recurring hijackings of AI assistants built into browsers, tracked over time.

Browser AI assistants such as Gemini, Copilot, Claude, and Perplexity Comet separate a cloud-based “brain” from an executing “body” in the browser – and security researchers have repeatedly exploited exactly this interface since summer 2026. In August, Zenity used PleaseFix to show how five browser assistants can be remotely controlled via email or calendar invite, with no user click required.

In September, Forever Security followed up with BragJack: this time, a single malicious browser extension is enough to hijack the same five assistants. Both findings exploit the same structural weakness – browser extensions and websites get blanket access to the communication between the AI agent and its cloud service – so further variants are likely until vendors change the underlying architecture.

Timeline

  1. Zenity finds zero-click vulnerability in five AI browsers

    Security researchers hijack Claude, Atlas, Gemini, Comet, and Copilot Edge via email – without any clicks from users.

  2. BragJack hijacks AI assistants in five browsers

    A security researcher demonstrates how a single extension remotely controls AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude.