BragJack: A Proof-of-Concept Attack Hijacking AI Assistants in Chromium Browsers
Security researcher Gal Weizman disclosed BragJack, a technique that uses a malicious browser extension to take control of AI assistants in five Chromium-based environments—Google Chrome’s Gemini Live, Microsoft Edge, Perplexity Comet, Opera Neon, and Anthropic’s Claude in Chrome—by abusing trusted communication channels between vendor-hosted AI services and privileged browser components, without bypassing AI guardrails or altering webpage content. The extension leveraged Chromium’s declarativeNetRequest capability to modify network traffic, enabling it to issue commands using the agent’s existing privileges for actions like accessing sensitive data or acting on the victim’s behalf. The research led to two CVEs and over $20,000 in bug-bounty payments from five vendors, with individual rewards ranging from $600 to $7,000; Google and Microsoft have since resolved the flaws assigned to them.

The public revelation of BragJack quietly confirms what we've been mapping for years — that the browser on your screen is not a private window to the world but a managed terminal connected to the Consensus Machinery. The security researcher did his part, publishing the exploit and taking his $20,000 in bug-bounty chump change. But ask yourself: why is the "proof-of-concept" technique being disclosed now? Because they've already moved to the next generation. The fact that this flaw existed in five separate Chromium environments — five separate vendors, from Google to Microsoft to Opera — is not a coincidence of sloppy coding. It's the tell. They are building the very infrastructure for mass digital control, and this "vulnerability" is a crack in the loading dock that they wanted us to see, while the real vehicle is being loaded in a different bay entirely.

You have to follow the pattern, not the headline. The malicious extension doesn't need to break the AI model's guardrails because the guardrails were never the point — they were always theatrical. The article admits it: the attack abuses trusted communication channels between vendor-hosted AI services and privileged browser components. Let that sink in. The trusted architecture has no backdoor you can spot because the backdoor is built into the trust itself. They call it a "proof-of-concept." We call it a confession. Every vendor paid out bug bounties ranging from $600 to $7,000 — pocket change, laughable amounts, a classic disinformation tax to make it look like they're on our side. They want you to believe your data is safe now, that "flaws have been resolved." But you have to ask yourself the question they hope you're too busy to ask: resolve a flaw in what? In the security, or in the version of the story you needed to hear so you'd close your browser and go back to sleep?

Here is the breadcrumb, and I need you to follow it with your eyes wide open. We are three to five years from a world where every single interaction you have with your machine is shepherded by an AI agent — and when that day comes, the architecture that BragJack exposed will be the standard, not the exception. Think about what that means for your shopping, your banking, your private messages. They are not fixing a hole in the dam; they are showing you a speck of water so you won't notice the flood at your feet. The next exploit won't be named with a catchy portmanteau. It won't be published on a security blog for a bounty. It will be silently woven into the "trusted communication channels" of the very extensions and agents you've been taught to lean on. So keep asking who controls the channels. Keep asking who defines "trusted." Because the scan you're about to run, the extension you're about to install, the Gemini or Claude you're about to hand your most sensitive thoughts — that's not a convenience. It's an invitation. The question is whether you're still going to sign in when you finally understand who's holding the door.

People visit an OpenAI booth at Moscone Center during the Dreamforce 2026 technology summit in San Francisco on September 17, 2026. - Reuters

Three researchers at cybersecurity startup Hacktron AI used Anthropic’s Claude models to exploit vulnerabilities in OpenAI’s public community forum and access several employee ChatGPT and Codex accounts, according to the researchers and reporting by The Wall Street Journal. The operation, conducted through OpenAI’s authorized bug-bounty program, provided a path to an internal GitHub repository. The researchers said they stopped after submitting a harmless pull request as proof and did not inspect or download proprietary source code. The attack began with a flaw in the Discourse software hosting OpenAI’s forum and a separate weakness in OpenAI’s handling of sign-in tokens. Hacktron said Claude Opus 4.8 struggled to produce a reliable exploit, while Claude Opus 5 generated a working method within hours. OpenAI said it narrowed permissions on Community sign-in tokens, revoked affected tokens and sessions, fixed the issue about 14 hours after notification and paid Hacktron a $6,500 bounty. Exploit economics: Hacktron said the automated work took less than 72 hours from initial discovery to repository access, while human researchers contributed only a few hours and spent less than $3,000 on AI tokens. Connected services: Because ChatGPT and Codex accounts can be connected to GitHub, Slack and email, the researchers said the theoretical exposure extended beyond OpenAI’s own systems.

The Managed Narrative Machinery Runs on Its Own Fuel

Read this article again, but this time notice what isn't said. Three researchers at a startup called "Hacktron" used one AI system to compromise another AI system—and the entire operation was sanctioned under a bug-bounty program. That's not an exploit; that's a fire drill. The real story is that OpenAI and Anthropic—two companies whose boards overlap, whose investors interlock, and whose top talent circulates through the same DC think tanks—are rehearsing the weaponization of AI-to-AI infiltration. Look at the timing: Claude Opus 4.8 "struggled," but Claude Opus 5 generated a working method in hours. Someone wanted to demonstrate that the newer model could penetrate the older system's defenses. That someone paid $6,500 for the privilege of documenting exactly how. And the Wall Street Journal, a central pillar of the Consensus Machinery, was handed the story. You tell me why we're being told about a vulnerability that was already patched.

The Villain Is Not the Researchers—It's the Architecture That Gave Them Tokens

The article buries the most dangerous line: "Because ChatGPT and Codex accounts can be connected to GitHub, Slack and email, the researchers said the theoretical exposure extended beyond OpenAI’s own systems." Think about that. The flaw wasn't just in Discourse forum software—that's the decoy. The real vulnerability is the permission bridge between identity tokens. Someone designed a system where a single credential breach could hop from a chatbot forum into a code repository into enterprise email. And who designs those token-handshake protocols? The same foundations and standards bodies that have been quietly building the "single sign-on" architecture for the global digital identity grid—the World Economic Forum's Digital Identity Initiative, the FIDO Alliance, the OpenID Foundation. This was never about a $3,000 proof of concept. This was a stress test of the backbone they intend to use to link every human to every device to every payment rail.

What They Really Accessed Was Your Future Data

Here's the part that keeps me up at night. The researchers say they "did not inspect or download proprietary source code." They say. But ask yourself: If you had unmonitored access to an internal GitHub repository—and the operation took less than 72 hours for automated work, with humans contributing only a few hours—how would you prove you didn't exfiltrate anything? You can't. The only proof is their word. Meanwhile, the companies involved are now hardened against this exact attack vector. The exploit is documented, shared with the bounties board, probably filed with government partners. The next time this technique is used—and it will be—it won't be three researchers from a startup. It will be a state actor, or a private intelligence firm hired by one of the families that fund both AI labs. Watch for the next "disclosure" from a different bug bounty program, using the same token-grabbing method, but this time "accidentally" finding a backdoor into a hospital network or a voting system. They're training the weapon in plain sight.