LIVE · cybersecurity feed
Live wire
CVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud Emails
ai

BragJack Attack Can Turn a Browser's Agentic AI Against It

A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

zeroday.news ·

A novel attack vector, dubbed "BragJack," has been identified that leverages the integrated agentic AI assistants within web browsers to compromise user data and execute unauthorized actions. This new method reportedly exploits the capabilities of these AI features, turning them against the user by manipulating their access to sensitive information and their ability to interact with web content. The core mechanism involves hijacking the AI assistant's functionality to achieve malicious objectives.

The BragJack attack reportedly operates by manipulating the browser's built-in AI assistant. While the specific technical details of the hijacking mechanism were not disclosed, this class of attack typically involves tricking the AI into misinterpreting user intent or into processing malicious input as legitimate commands. This could potentially involve prompt injection techniques, where specially crafted web content or user interactions lead the AI to perform actions unintended by the user. Given the AI's direct integration into the browser, it likely possesses elevated privileges or access to browser functions that a standard web script might not.

Once hijacked, the agentic AI assistant can reportedly be coerced into accessing sensitive information. This might include data visible within the browser context, such as information displayed on web pages, autofill data, or potentially even session tokens if the AI has access to such elements. The scope of accessible information would depend on the specific permissions and capabilities granted to the AI assistant by the browser vendor.

Beyond data access, the attack also enables the execution of malicious actions. This could encompass a wide range of activities, such as navigating to malicious websites, altering browser settings, clicking on specific elements, or even initiating downloads. The ability to execute actions via the AI assistant effectively grants an attacker a degree of programmatic control over the user's browsing experience, bypassing traditional security controls that might block direct script execution.

A critical reported capability of the BragJack attack is data exfiltration. After accessing sensitive information, the hijacked AI assistant can reportedly be instructed to transmit this data to an attacker-controlled destination. This could occur through various means, such as sending the data via web requests initiated by the AI, or potentially by manipulating web forms to submit the information. The effectiveness of exfiltration would depend on the AI's network access and its ability to interact with external resources.

Mitigation strategies for this class of attack typically focus on securing the AI's input and output channels, as well as limiting its permissions. Browser vendors may need to implement more robust input validation for AI prompts, enhance sandboxing for AI-driven actions, and carefully review the scope of data and functionalities accessible to the agentic AI. Users are generally advised to exercise caution when interacting with AI features and to be wary of unexpected AI behaviors, though the nature of this attack suggests it may be difficult for an untrained user to detect.

The emergence of the BragJack attack highlights a growing security concern as agentic AI capabilities become more deeply integrated into user-facing applications like web browsers. As these AI assistants gain more power and access to user data and system functions, they present new attack surfaces that require novel security considerations. This incident underscores the ongoing challenge of securing complex AI systems against sophisticated manipulation techniques.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

First Agentic AI Data Breach Reported to Spanish Regulator

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.

ai

Self-improving AI should slow down, von der Leyen tells EU lawmakers

European Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that. In her State of the Union address to the European Parliament in Strasbourg, she also committed the EU to joint work with Canada, the U.K. and other partners on evaluating and verifying

vulnerability

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether what survives can be attacked. Pipelines are written in YAML, the code is Python 3.11 and up. Rehman Ahmadzai, who maintains the project, said DeepZero h

CVE-2026-89026critical

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded

nation-state

Fake CAPTCHA Scams

New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.

CVE-2026-58704high

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database