。截至截稿前,我们未收到 Perplexity、Opera 或 Anthropic 的回复。在下一次 AI 攻击来临前锁定你的 ChatGPT 账户你可能已经听说过提示词注入。这通常涉及在 AI 读取的内容中隐藏恶意指令。Weizman 称这种新方法为“提示词强制”。在这里,攻击者不需要将指令隐藏在网页中并希望 AI 遵循它们。攻击者可以通过浏览器或助手信任的渠道,将完整的提示词强制植入代理中。AI 随后可以将这条纯英语指令转化为合法的浏览器操作。这给安全软件带来了一个有趣的问题。窃取邮件的可疑程序可能更容易被发现。但经过批准的 AI 代理打开网站并点击按钮,看起来就像正常的浏览器活动。
AI assistants are moving deeper into the browsers we use every day. They can summarize a webpage, explain what you are looking at and, in some cases, take action on websites for you. That convenience also gives these tools access that a normal webpage would never have. Now, security researcher Gal Weizman of Forever Security has shown how a malicious browser extension could potentially turn those powerful AI capabilities against you. His research, called BragJack, targeted Gemini Live in Chrome, Perplexity Comet, Microsoft Edge Actions, Opera Neon and Anthropic's Claude in Chrome. The findings resulted in more than $20,000 in bug bounties and two CVEs. There is one important detail before you panic. The attack still required the malicious extension to be installed first. After that, Weizman demonstrated attacks that needed zero additional clicks from the victim. So how could one extension get that far inside the browser? It comes down to how these AI assistants are built. Missed CyberGuy LIVE? Watch the replay and discover 5 ways AI can help you get better healthcare. Our free CyberGuy LIVE class, Get Better Healthcare With AI, has ended, but you can still watch the full replay. Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed.
已发布的 BragJack 研究描述了概念验证攻击,并未报告这些技术已在实际环境中被利用。尽管如此,该研究展示了随着 AI 代理获得对浏览器和计算机的更深层访问权限,安全方程式是如何发生变化的。
AI MALWARE CAN REWRITE ITSELF TO EVADE DETECTION Weizman describes these AI systems as having a "brain" and a "body." The AI model works out what should happen. A privileged component inside the browser then carries out the request. Depending on the product, that privileged component might read webpage content, capture a screenshot or interact with a website. That setup becomes risky if something else inside the browser can manipulate the connection between those pieces. The proof-of-concept attacks relied heavily on Chromium's declarativeNetRequest, or DNR, system. Browser extensions can use DNR to modify how network requests work. That can include changing response headers or redirecting resources. Forever Security showed how those capabilities could let an extension interfere with web content trusted by a browser's AI features.
攻击始于我们许多人几乎不再考虑的事物:浏览器扩展。CyberGuy 曾报道过伪装成 AI 助手的恶意扩展、劫持在线账户,甚至将受信任的扩展变成窃取数据的间谍软件。这使得清理扩展成为你现在可以采取的最简单步骤之一。也许你两年前安装了一个优惠券扩展然后忘了它。也许你曾测试过一个 AI 侧边栏一次后就再没打开过。如果你不再需要某个扩展,就没有理由继续授予它访问浏览器的权限。
Chrome was one of the more striking examples. Google's Gemini side panel essentially has two pieces. Gemini handles the intelligence behind the request while Chrome provides the browser-level abilities needed to carry it out. Researchers found that Chrome already prevented extensions from directly injecting scripts into the Gemini page. However, the researchers discovered that an extension could still manipulate certain network requests used inside the Gemini experience. That gap allowed Weizman to demonstrate access to browser capabilities that the extension itself should never have received. According to the research, he could access local files, capture screenshots and obtain browser profile information. The researcher says the flaw also let him turn on the camera and microphone with zero clicks from the user. Google awarded the researchers a $7,000 bounty for reporting the vulnerability, which received the identifier CVE-2026-0628. Google has since confirmed to CyberGuy that it has closed this specific attack path. A Google spokesperson told us, "Confirming we've released a patch in Chrome so this method no longer works on the Gemini side panel." That means the technique demonstrated by the researchers should no longer work against the Gemini side panel in an updated version of Chrome.
浏览器会定期接收安全修复,因此一旦有更新可用请立即安装。谷歌的回应使这一点尤为相关。该公司表示,已发布 Chrome 补丁,阻止了研究人员演示的 Gemini 侧边栏攻击方式。如果更新后提示重启 Chrome,请重启以便最新版本完成安装。
Perplexity Comet raised a different concern because its AI agent can take actions inside websites. Weizman found that Comet's built-in agent trusted several Perplexity domains. One testing domain lacked the same extension protections used on the main Perplexity site. Normally, that testing address redirected elsewhere. The proof-of-concept used DNR to remove the redirect and load the page instead. That gave the extension a path to communicate with Comet's built-in agent. The demonstrated access included browsing history, screenshots and local files. Then things became more personal. Weizman demonstrated sending an instruction that told the agent to access Perplexity, summarize the victim's recent emails and send the information to another email address. The AI agent performed the browser actions using capabilities it already had.
打开浏览器的扩展管理器,移除任何你不认识或不再使用的扩展。以下是最快的检查方法:Chrome 和 Chrome 中的 Claude:点击三点菜单 → 扩展程序 → 管理扩展程序 → 找到该扩展 → 移除。Google 在其当前的 Chrome 说明中确认了此路径。
Microsoft built safeguards into Edge to keep outside prompts from easily controlling what its AI agent could do. Researchers still found a way around them. Weizman discovered a timing flaw known as a race condition. In simple terms, his test extension could feed the AI a prompt and then quickly switch on its ability to take action before Edge finished checking whether the request should be allowed. That opened the door for the AI agent to carry out a command it should not have accepted. Microsoft tracked the flaw as CVE-2026-55945 and rated it medium severity. The company says Edge versions before 150.0.4078.48 were affected. Updating Edge closes this particular security hole.
Microsoft Edge:点击扩展拼图图标 → 管理扩展 → 找到该扩展 → 移除。
Forever Security also demonstrated related attacks against Opera Neon and Claude in Chrome. There is an important difference with Claude. Claude in Chrome is itself a browser extension, rather than a complete browser. The researcher found that a page on Claude's domain could send prompts to the extension's side panel. Another extension could manipulate that trusted page and force prompts into Claude. Forever Security says Anthropic awarded a bounty for the finding and classified it as medium severity. Opera Neon also allowed the proof-of-concept extension to reach its AI agent. According to the researcher, that access could force the agent to carry out instructions on websites. All five demonstrations were Chromium-based, which helped the researcher reuse the same basic attack approach.
Opera Neon:从浏览器侧边栏或菜单打开扩展区域 → 查看已安装的扩展 → 移除任何你不再信任或使用的扩展。Opera 通过扩展图标和菜单记录了其扩展管理器。
Forever Security also demonstrated related attacks against Opera Neon and Claude in Chrome. There is an important difference with Claude. Claude in Chrome is itself a browser extension, rather than a complete browser. The researcher found that a page on Claude's domain could send prompts to the extension's side panel. Another extension could manipulate that trusted page and force prompts into Claude. Forever Security says Anthropic awarded a bounty for the finding and classified it as medium severity. Opera Neon also allowed the proof-of-concept extension to reach its AI agent. According to the researcher, that access could force the agent to carry out instructions on websites. All five demonstrations were Chromium-based, which helped the researcher reuse the same basic attack approach.
Perplexity Comet:打开浏览器的扩展管理器并查看导入或安装的 Chrome 扩展。Comet 支持 Chrome 扩展,并可从 Chrome 导入它们。
We reached out to Google, Microsoft, Perplexity, Opera and Anthropic for comment on the research. Google responded with the update included above. Microsoft pointed us to its CVE-2026-55945 security advisory and said it had nothing further to share. We did not hear back from Perplexity, Opera or Anthropic before our deadline.
专业提示:如果你不确定某个扩展,请先禁用它,在移除前调查其开发者。
LOCK DOWN YOUR CHATGPT ACCOUNT BEFORE THE NEXT AI ATTACK You may already have heard about prompt injection. That usually involves hiding malicious instructions in something an AI reads. Weizman calls this new approach Prompt Forcing. Here, the attacker does not need to hide instructions inside a webpage and hope the AI follows them. The attacker can force a complete prompt into the agent through a channel that the browser or assistant trusts. The AI can then turn that plain-English instruction into legitimate browser actions. That creates an interesting problem for security software. A suspicious program stealing an email may be easier to spot. An approved AI agent opening a website and clicking a button can look like normal browser activity. The published BragJack research describes proof-of-concept attacks and does not report that these techniques have been exploited in the wild. Still, the research shows how the security equation changes as AI agents receive deeper access to browsers and computers.
数千个被黑网站诱骗你安装恶意软件 当扩展请求对网站或浏览器活动的广泛访问权限时,请仔细查看。该权限应与扩展的实际功能相符。
LOCK DOWN YOUR CHATGPT ACCOUNT BEFORE THE NEXT AI ATTACK You may already have heard about prompt injection. That usually involves hiding malicious instructions in something an AI reads. Weizman calls this new approach Prompt Forcing. Here, the attacker does not need to hide instructions inside a webpage and hope the AI follows them. The attacker can force a complete prompt into the agent through a channel that the browser or assistant trusts. The AI can then turn that plain-English instruction into legitimate browser actions. That creates an interesting problem for security software. A suspicious program stealing an email may be easier to spot. An approved AI agent opening a website and clicking a button can look like normal browser activity. The published BragJack research describes proof-of-concept attacks and does not report that these techniques have been exploited in the wild. Still, the research shows how the security equation changes as AI agents receive deeper access to browsers and computers.
某些浏览器允许你决定扩展是可在所有网站运行,还是仅在特定网站运行。仅授予扩展工作所需的最小权限。
LOCK DOWN YOUR CHATGPT ACCOUNT BEFORE THE NEXT AI ATTACK You may already have heard about prompt injection. That usually involves hiding malicious instructions in something an AI reads. Weizman calls this new approach Prompt Forcing. Here, the attacker does not need to hide instructions inside a webpage and hope the AI follows them. The attacker can force a complete prompt into the agent through a channel that the browser or assistant trusts. The AI can then turn that plain-English instruction into legitimate browser actions. That creates an interesting problem for security software. A suspicious program stealing an email may be easier to spot. An approved AI agent opening a website and clicking a button can look like normal browser activity. The published BragJack research describes proof-of-concept attacks and does not report that these techniques have been exploited in the wild. Still, the research shows how the security equation changes as AI agents receive deeper access to browsers and computers.
使用熟悉 AI 名称的扩展可能与该 AI 服务背后的公司毫无关联。安装前请核实发布者。
The attack starts with something many of us barely think about anymore: a browser extension. CyberGuy has covered malicious extensions that pretended to be AI assistants,hijacked online accounts and even turned trusted extensions into data-stealing spyware. That makes extension cleanup one of the easiest steps you can take right now. Maybe you installed a coupon extension two years ago and forgot about it. Perhaps you tested an AI sidebar once and never opened it again. If you no longer need an extension, there is little reason to keep giving it access to your browser.
如果浏览器提供禁用你从未使用的 AI 助手或代理的选项,请考虑将其关闭。这能减少在其他组件被攻破时可利用的强大浏览器功能数量。
The attack starts with something many of us barely think about anymore: a browser extension. CyberGuy has covered malicious extensions that pretended to be AI assistants,hijacked online accounts and even turned trusted extensions into data-stealing spyware. That makes extension cleanup one of the easiest steps you can take right now. Maybe you installed a coupon extension two years ago and forgot about it. Perhaps you tested an AI sidebar once and never opened it again. If you no longer need an extension, there is little reason to keep giving it access to your browser.
强大的杀毒软件可以帮助标记恶意下载和与不良扩展相关的可疑活动。如果有东西溜过了你的眼睛,它还能增加一层保护。请访问 Cyberguy.com 查看我为您的 Windows、Mac、Android 和 iOS 设备精选的 2026 年最佳杀毒保护获奖产品。不要仅仅因为某扩展听起来在五分钟内有用就安装它。每个扩展都会向您用于电子邮件、银行、购物和其他私人活动的浏览器添加代码和权限。
Browsers receive security fixes regularly, so install updates as soon as they become available. Google's response makes that especially relevant here. The company says it has already released the Chrome patch that blocks the Gemini side-panel method demonstrated by the researchers. Restart Chrome after an update if prompted so the newest version can finish installing. Open your browser's extension manager and remove anything you do not recognize or no longer use. Here is the quickest way to check: Chrome and Claude in Chrome: Click the three-dot menu → Extensions → Manage extensions → find the extension → Remove. Google confirms this path in its current Chrome instructions. Microsoft Edge: Click the Extensions puzzle-piece icon → Manage extensions → find the extension → Remove. Opera Neon: Open the Extensions area from the browser sidebar or menu → review your installed extensions → remove anything you no longer trust or use. Opera documents its extensions manager through the Extensions icon and menu. Perplexity Comet: Open the browser's extensions manager and review imported or installed Chrome extensions. Comet supports Chrome extensions and can import them from Chrome. Pro tip: If you are unsure about an extension, disable it first and research the developer before removing it.
引起我注意的是,当 AI 代理介入时,一个恶意浏览器扩展可能变得强大多少。我们早已知道扩展能监视浏览或窃取账户数据。这项研究展示了一条通往拥有更广泛特权事物的可能路径。这里也有一个实用的启示。这些演示仍然需要攻击者控制的扩展先进入浏览器。然而,一旦它进入了,研究人员展示了攻击可以在受害者无需再次点击的情况下继续。我建议您花五分钟时间,今天就检查一下您的扩展。如果您记不起来为什么安装了某个扩展,请弄清它的功能。如果您几个月前就停止使用它了,请将其移除。随着浏览器 AI 变得更强大,构建这些工具的公司也需要在普通扩展和允许 AI 代表我们行动的特权系统之间建立强有力的屏障。
THOUSANDS OF HACKED SITES TRICK YOU INTO INSTALLING MALWARE Look carefully when an extension asks for broad access to websites or browser activity. The permission should make sense for what the extension actually does. Some browsers let you decide whether an extension can run on every website or only certain sites. Give an extension the narrowest access it needs to work. An extension that uses a familiar AI name may have no connection to the company behind that AI service. Check the publisher before installing it. If your browser gives you the option to disable an AI assistant or agent you never use, consider turning it off. That reduces the number of powerful browser features available if another component gets compromised. Strong antivirus software can help flag malicious downloads and suspicious activity connected to bad extensions. It adds another layer of protection if something slips past you. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com Do not install one because it sounds useful for five minutes. Every extension adds code and permissions to the browser you use for email, banking, shopping and other private activity. What gets my attention here is how much more powerful a bad browser extension can become when an AI agent enters the picture. We already knew extensions could spy on browsing or steal account data. This research shows a possible path to something with much broader privileges. There is also a practical takeaway. These demonstrations still required the attacker-controlled extension to get inside the browser first. Once it was there, however, the researcher showed that the attack could continue without another click from the victim. I would take five minutes and look through your extensions today. If you cannot remember why you installed one, find out what it does. If you stopped using it months ago, remove it. As browser AI grows more capable, the companies building these tools also need strong barriers between ordinary extensions and the privileged systems that let AI act for us.
如果恶意扩展可能将这种访问权限用来对付您,您还会让 AI 助手控制浏览器的部分功能吗?请写信至 Cyberguy.com 告诉我们您的想法。注册我的免费 CyberGuy 报告
Would you still let an AI assistant control parts of your browser if a malicious extension could potentially turn that access against you? Let us know by writing to us at Cyberguy.com Sign up for my FREE CyberGuy Report