Preliminary research
Site Isolation is Dead: How Site Isolation is Broken in Agentic Browsers and Extensions
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Site isolation separates renderer processes per origin, but an agentic browser's whole purpose is to act across that boundary. Two open-source agentic browsers and seven agentic extensions share one architecture - privileged processes hold the prompts and agent operations, untrusted renderers are isolated, IPC bridges them - and two end-to-end attacks cross that IPC: prompt injection, and LLM data exfiltration.
Record
- Researcher
- Suyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin, Sanghyun Hong, Byoungyoung Lee and Sooel Son
- Published by
- wsp-lab.github.io
- Format
- Whitepaper
- Topic
- Browser
In the archive
Related sources
- Site Isolation is Dead: How Site Isolation is Broken in Agentic Browsers and Extensions (Artifacts) Repository
Tags
This page is the archive's own catalogue record. The research is the work of Suyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin, Sanghyun Hong, Byoungyoung Lee and Sooel Son, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .