
BragJack: one ordinary extension commanded Claude in Chrome, Gemini Live, Edge, Comet, and Opera Neon. Forever Security took over the page the agent body already trusts, then sent it orders. Chrome got CVE-2026-0628. Edge got CVE-2026-55945. Comet, Neon, and Claude in Chrome have no CVE in their table. if you run those agents, check chrome://extensions for declarativeNetRequest you didn't mean to grant.
