ACVEAgent configuration vulnerability registry

ACVE-2026-0438

Exposed files, browsing data or browser actions on instructions from a malicious extension: the built-in agents in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome, in normal browsing.

Exposure

Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

ClaimStatusSourceChecked
Identifier CVE-2026-0628Confirmedcveawg.mitre.org2026-09-24
Identifier CVE-2026-55945Confirmedcveawg.mitre.org2026-09-24
Severity HIGH; matches ADP/NVDConfirmedcveawg.mitre.org2026-09-24

In the wild

demonstrated

Description

What

Forever Security and BleepingComputer reported five browser-agent demonstrations under the BragJack name. A malicious extension could cause the built-in assistants to read local or browser data, take screenshots or act on websites; Chrome and Edge assigned CVE identifiers.

Detection

The researchers demonstrated the behavior across five browser agents.

Fix

Keep browsers and agent extensions updated, remove untrusted extensions and avoid granting broad extension permissions.

Fix

Update the affected browsers and remove untrusted extensions.

  • Reconfigure browser.extensions to remove untrusted extensions and restrict permissions. The reports identify malicious extensions as the common input to the browser agents. Owner: operator

References

ARTICLE

Report a problemJSON