< ciso
brief />
Tag Banner

All news with #browser security tag

123 articles

Leveraging browser telemetry for proactive defense

🔒 Modern browsers are central enterprise workspaces and require embedded security. Chrome Enterprise Premium captures high-fidelity browser telemetry to surface in-browser threats that legacy EDR and perimeter tools miss, including risks from shadow AI and autonomous agents. Streaming these signals into security operations enables proactive mitigation, automated response, and reduced investigation time, demonstrated in Mandiant case studies.
read more →

Six Browser-Based Attack Techniques Threatening 2026

🛡️ The browser has become the primary battlefield for modern breaches, with attacks spanning credential phishing, session hijacking, and authorization abuse. Vendors report commoditized kits that relay live sessions and bypass MFA, while new vectors like ClickFix trick users into executing malicious commands locally. Malicious extensions, OAuth consent scams, credential stuffing, and stolen session tokens further enable account takeover and data exfiltration. Organizations must extend defenses into the browser to detect and block these evolving threats in real time.
read more →

BragJack: Malicious Extensions Hijack Browser AI

🔒 Security researcher Gal Weizman of Forever Security disclosed a proof-of-concept attack named BragJack that uses a single malicious Chromium extension to hijack built-in AI browser agents. The technique, demonstrated against Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude for Chrome, exploits Chromium's declarativeNetRequest to intercept and modify trusted resources, enabling agents to access files, history, screenshots, and act on users' behalf. Vendors issued fixes and paid bug bounties, and the researcher published a full technical breakdown.
read more →

Malicious browser extensions enable ClickFix attacks

🛡️ This post explains how browser extensions can be abused to deliver ClickFix social-engineering attacks, using a recent campaign that pushed 19 malicious add‑ons through official stores as an example. It describes how extensions gain wide permissions, how attackers acquire or buy extensions, and how updates and C2 modules let them inject malicious code into otherwise legitimate pages. The article highlights modules that steal credentials, drain crypto wallets, prompt for seed phrases, and serve ClickFix instructions that can break out of the browser and install system‑level malware.
read more →

Browser extension can hijack built‑in AI agents

🔒 Security researchers at Forever Security demonstrated that a single ordinary browser extension can commandeer built‑in AI assistants in five Chromium‑based products: Chrome (Gemini Live), Perplexity Comet, Microsoft Edge, Opera Neon and Claude in Chrome. The exploit required only two common permissions and let the extension inject code into the trusted AI page to send commands to the agent. Google and Microsoft have issued patches for Chrome and Edge; Perplexity, Opera and Anthropic paid bounties but have not publicly fixed the exact methods described. Forever Security emphasized the attacks are proof‑of‑concepts requiring the malicious extension to be already installed.
read more →

Palo Alto Networks joins Zendesk Startup Program

🔒 Palo Alto Networks partners with the Zendesk Startup Program to offer startups enterprise-grade browser security. The post explains how Prisma Browser for Business (PBB) protects support agents and customer data by blocking phishing, preventing data leakage, and applying tailored policies to Zendesk sessions. The program allows eligible startups to access PBB with minimal setup, helping founders build securely from day one while preserving runway.
read more →

Trusted Chrome and Edge extensions weaponized

🔍 Researchers at Socket found a supply-chain campaign that turned 19 Chrome and Edge extensions into malware by acquiring or publishing updates to previously legitimate extensions. The attackers used automatic extension updates to push malicious JavaScript payloads that stole cryptocurrency, captured form input, hijacked active sessions, and exfiltrated social media access and browsing history. Several extensions had substantial user bases, underscoring the reach of the operation.
read more →

Malicious Firefox Add‑Ons Target Crypto Wallets

🔒 Security researchers at Socket uncovered a campaign of linked Firefox add‑ons designed to steal cryptocurrency wallet seed phrases and browser credentials. Dubbed the "Offside Wallet Theft Factory," the operation has been active since at least March 2026 and uses minimal‑permission extensions that switch behavior via a Supabase backend. Some extensions pose as wallets, VPNs, or utilities while others impersonate sports score tools, and attackers remotely toggle malicious pages to harvest recovery phrases and passwords. Out of 77 linked add‑ons, 40 were confirmed to steal data, illustrating how shared code and infrastructure enable rapid weaponization.
read more →

40 Malicious Firefox Extensions Target Web3 Wallets

🛡️ A cluster of 40 malicious Mozilla Firefox extensions has been identified stealing cryptocurrency wallet secrets by impersonating popular Web3 products like OKX, Rabby Wallet, and TronLink. Socket Threat Research attributes the extensions to a broader set of 77 related add-ons with shared code and infrastructure, a campaign they call Offside Wallet Theft Factory, active since March 2026. The threat actors used Supabase projects, Cloudflare Workers, and hard-coded C2 to exfiltrate recovery phrases, private keys, and credentials, often hiding malicious payloads behind benign sports-score or utility shells. Researchers warn the economics of disposable extensions and repurposing identities make the Firefox Add-ons ecosystem an attractive target.
read more →

New macOS infostealer hijacks browsers for remote control

🛡️ Jamf Threat Labs uncovered a multi-stage macOS infostealer named AmnesiaStealer that uses a fake GitHub download page to trick victims into running a Terminal command which installs malware. The Rust-based loader retrieves a password-protected ZIP, deploys a universal Mach-O payload and collects passwords, Keychain items, browser data and other sensitive files. A distinct stream_module converts the victim’s Chromium browser into a remotely controlled session via WebSocket, allowing attackers to export cookies and perform browsing actions.
read more →

Chrome reduces Android notification abuse by billions

🔔 Google reports that Chrome's anti-abuse systems blocked over 7 billion unwanted Android notifications per day in Q1 2026. The company says notification abuse has become a vector for scams, malware, phishing, and fraudulent payment requests, prompting a layered "Swiss cheese" defense model. Chrome now auto-revokes notification permissions from inactive or repeatedly abusive sites and allows users to review and restore access via Safety Hub. The browser also limits message rates for disruptive sites and adjusted permission prompts to be less intrusive on Android.
read more →

Unified Browser and Endpoint Security Integration

🛡️ Palo Alto Networks announces native integration between Prisma Browser and Cortex XDR, closing critical SOC visibility gaps by turning the browser into an active security sensor. This integration feeds browser telemetry—DLP violations, tampering, and configuration changes—directly into Cortex, enabling correlated alerts and precise, surgical containment without disrupting user productivity. The approach avoids brittle extensions and provides deep, real-time context for investigations.
read more →

Cloudflare launches Kitesurf: a browser for agents

🛰️ Kitesurf is a new browser built by Cloudflare to run entirely on top of Workers and optimized for AI agents. It targets agentic tasks by being far more efficient in CPU and memory than Chromium for common operations like screenshots and HTML extraction. The design emphasizes isolation, stateless components, robust exception handling, and extensive testing using Web Platform Tests plus integration and visual regression suites. Kitesurf’s architecture separates the Engine, PageScript, and PageRenderer, uses Rust-compiled WebAssembly where possible, and enforces network access through a SandboxOutbound worker to minimize risk.
read more →

WebKit proxy bypasses can expose real IPs

🔒 Researchers disclosed that features in Apple's WebKit can bypass configured proxies and reveal users' real IP addresses, affecting iCloud Private Relay. The flaw stems from DNS prefetching, WebAuthn related origin requests, and WebTransport, which send traffic outside the relay. A PoC site demonstrates the leak, and Apple says it is investigating while the issue also impacts macOS and other WebKit-based browsers.
read more →

Securing Agentic Browsing in Chrome Enterprise

🔒 This blog explains how Chrome Enterprise is adapting browser security for autonomous AI agents operating in enterprise web workflows. It highlights the browser's contextual advantage for anchoring agentic actions to corporate identity and access controls, and describes how features like integrated Data Loss Prevention and enhanced visibility help mitigate new data exposure vectors. The post also outlines layered protections, red-teaming, and expanded vulnerability rewards to strengthen agent security.
read more →

Chrome to block policy-installed new-tab hijackers

🛡️ Google is developing a Chrome security feature to block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged consumer devices. The change, spotted in Chromium Gerrit, would enable a feature flag by default to prevent extensions forced by local policies from overriding the New Tab or search settings. Chrome would cancel such installations, record the extension ID as blocked, and avoid repeated download attempts, while allowing administrators an escape hatch policy when needed.
read more →

Patched Firefox JIT Bug Enabled Remote Code Execution

🛡️ Nebula Security disclosed a high-severity Firefox JIT vulnerability, tracked as CVE-2026-10702, that could be triggered simply by visiting a malicious webpage and was used to compromise Tor Browser builds embedding affected Firefox versions. Mozilla fixed the flaw in Firefox 151.0.3 and rated it High; the bug allows arbitrary code execution in the browser renderer process and was exploited by Nebula as the initial stage of their IonStack browser-to-kernel chain on an ARM64 Android 17 build. Users are urged to update to the latest Firefox release.
read more →

Claude Chrome extension flaw lets malicious extensions act

🛡️ A vulnerability in Anthropic's Claude for Chrome extension can let a malicious extension simulate clicks to trigger nine predefined AI workflows. The issue, found by Ax Sharma of Manifold Security, stems from the extension failing to verify the browser's Event.isTrusted flag before executing tasks tied to page click handlers. A malicious extension with permissions on claude.ai could inject elements and fire synthetic clicks to abuse Claude's authenticated access to services like Gmail, Docs, Calendar, and Salesforce. Anthropic acknowledged the report and classified a related skipPermissions parameter as informational.
read more →

New Claude for Chrome bugs let extensions abuse privileges

🔒 Researchers at Manifold Security found two vulnerabilities in Anthropic’s Claude for Chrome extension that let a malicious extension trigger privileged AI actions, including reading Gmail, Google Docs, and Calendar data. The flaws are reproducible in version 1.0.80 and persist eight releases after initial reporting. One issue allows synthetic clicks to bypass user verification due to missing event.isTrusted checks; the other places the extension into an elevated mode via a URL parameter. Manifold urges fixes to validate genuine user interactions and to avoid URL-driven privilege transitions.
read more →

Study Reveals Browser Wallets Enable Cross‑Site Tracking

🔎 Researchers at KU Leuven analyzed 85 popular browser-based crypto wallet extensions and found systemic privacy leaks that can link and de-anonymize users. The wallets reveal addresses in clear text to external servers, announce installed wallets to sites, and often fail to revoke access on logout. These behaviors allow separate addresses to be correlated, stale permissions to persist across sessions, and authorized wallets to expose addresses inside embedded frames, enabling cross-site tracking and potential deanonymization.
read more →