Follow the latest coverage, related explainers and connected technology stories.
Security researcher Gal Weizman revealed a proof-of-concept technique called BragJack that exploits a malicious browser extension to take control of artificial intelligence assistants in five browsers and services, potentially enabling the reading of files and browsing data and the execution of actions on behalf of the user. The research earned more than $20,000 in bug bounty rewards and resulted in CVE assignments.
An active banking operation since mid-2025 has used the KREMLIN tool to install malicious extensions on Chrome and Edge without user consent, aiming to steal passwords, tokens, sessions, and sensitive data. Elastic Security Labs identified approximately 1,515 infected systems, most of them in Brazil, and managed to disrupt the current campaign by exploiting an anti-analysis check.
Socket uncovered a campaign that used 19 extensions for Google Chrome and Microsoft Edge to distribute a malicious software framework capable of stealing cryptocurrency, account data, and browsing history, while injecting fraudulent ClickFix pages. The investigation’s findings indicate that the activity may have started as early as the beginning of 2024, and that some extensions became malicious tools after attackers acquired them and automatically updated them.