KREMLIN malware uses a sophisticated technique to bypass Chromium's integrity checks, allowing it to force-install malicious browser extensions that steal session tokens and credentials.
Researchers found that malicious browser extensions could hijack AI assistants in Chrome and Edge, potentially allowing attackers to access files and control AI agents.
Researchers have discovered BragJack, a novel attack that hijacks agentic AI in browsers by exploiting the communication channel between extensions and AI agents.