Web Hack List

Preliminary research

Site Isolation is Dead: How Site Isolation is Broken in Agentic Browsers and Extensions

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Site isolation separates renderer processes per origin, but an agentic browser's whole purpose is to act across that boundary. Two open-source agentic browsers and seven agentic extensions share one architecture - privileged processes hold the prompts and agent operations, untrusted renderers are isolated, IPC bridges them - and two end-to-end attacks cross that IPC: prompt injection, and LLM data exfiltration.

Record

Researcher
Suyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin, Sanghyun Hong, Byoungyoung Lee and Sooel Son
Published by
wsp-lab.github.io
Format
Whitepaper
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Suyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin, Sanghyun Hong, Byoungyoung Lee and Sooel Son, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .