Web Hack List

Preliminary research

BragJack: extension access to privileged browser-agent channels

BragJack [Technical Overview]: How We Hijacked Top 5 Browsers' Internal Agents With Just One Single Extension

AI-collected research leads through 24 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Shows how extension-controlled network rules and trusted web origins reach privileged browser-agent interfaces. Comet exposes an unprotected testing origin; Edge combines weakened framing policy, debugger-generated gestures and a tools-mode race. Includes distinct Chrome, Opera and Claude paths.

Record

Document
BragJack [Technical Overview]: How We Hijacked Top 5 Browsers' Internal Agents With Just One Single Extension
Researcher
Gal Weizman
Published by
Forever Security
Date
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Gal Weizman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .