ACVE-2026-0438
Exposed files, browsing data or browser actions on instructions from a malicious extension: the built-in agents in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome, in normal browsing.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
| Claim | Status | Source | Checked |
|---|---|---|---|
| Identifier CVE-2026-0628 | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Identifier CVE-2026-55945 | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Severity HIGH; matches ADP/NVD | Confirmed | cveawg.mitre.org | 2026-09-24 |
In the wild
demonstrated
Description
What
Forever Security and BleepingComputer reported five browser-agent demonstrations under the BragJack name. A malicious extension could cause the built-in assistants to read local or browser data, take screenshots or act on websites; Chrome and Edge assigned CVE identifiers.
Detection
The researchers demonstrated the behavior across five browser agents.
Fix
Keep browsers and agent extensions updated, remove untrusted extensions and avoid granting broad extension permissions.
Fix
Update the affected browsers and remove untrusted extensions.
- Reconfigure
browser.extensionstoremove untrusted extensions and restrict permissions. The reports identify malicious extensions as the common input to the browser agents. Owner: operator