Security researcher Gal Weizman demonstrated how malicious browser extensions could hijack AI assistants in Chrome, Edge, and other browsers through the BragJack research. The attack exploited how AI systems separate their decision-making from browser execution, allowing extensions to manipulate network requests and gain unauthorized access to files, screenshots, and device capabilities. The findings earned over $20,000 in bug bounties and prompted vendors including Google to release patches.