According to the new Browser Security Report 2025, security leaders are finding that the risks associated with SaaS and AI converge at a single point: the user’s browser. However, traditional controls like DLP, EDR, and SSE still operate one layer below.
See also: Firefox: New extensions must declare data collection practices

What’s emerging isn’t just a blind spot. It’s a parallel threat landscape: unmanaged extensions that act like supply chain implants, GenAI tools accessed through personal accounts, sensitive data copied/pasted directly into prompt fields, and sessions that bypass SSO entirely.
This article analyzes the report's key findings and what they reveal about the changing audit focus on enterprise security.
GenAI is now the leading data extraction channel
The rise of GenAI in business workflows has created a huge governance gap. Nearly half of employees use GenAI tools, but most do so through unmanaged accounts, outside of IT visibility.
Key statistics from the report include:
– 77% of employees paste data into GenAI prompts
– 82% of these pastes come from personal accounts
– 40% of uploaded files contain PII or PCI
– GenAI accounts for 32% of all corporate-to-personal data traffic
Traditional DLP tools were not designed for this. The browser has become the dominant channel for copy/paste data extraction, without monitoring and without policies.
AI browsers are an emerging threat surface
Another emerging browser-based threat surface is 'agentic' AI browsers, which combine traditional browser security risks with new concerns about the use of AI.
AI browsers like OpenAI’s Atlas, Arc Search, and Perplexity Browser are redefining how users interact with the web, merging search, conversation, and browsing into a single intelligent experience. These browsers embed large language models directly into the browsing layer, allowing them to read, summarize, and reason on any page or tab in real time. For users, this means seamless productivity and content-based assistance. But for businesses, this represents a new and largely unmonitored attack surface: an “always-on collaborator” that silently sees and processes whatever an employee can see, without enforcing policies or visibility into what is shared with the cloud.
See also: AI browsers abused by malicious AI sidebar extensions

The risks are significant and multifaceted: session memory leaks expose sensitive data through AI personalization, invisible “auto-prompting” sends page content to third-party models, and shared cookies blur identity boundaries, allowing for potential takeovers. Without enterprise-level protections, these AI browsers essentially bypass traditional DLP, SSE, and browser security tools, creating an invisible, fileless path to data extraction. As organizations adopt GenAI and SaaS workflows, understanding and addressing this emerging blind spot is critical to preventing the next generation of data leaks and identity breaches.
Browser Extensions: The Most Widespread and Least Controlled Supply Chain
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
99% of business users have at least one extension installed. Over half grant high or critical permissions. Many are either sideloaded or published from Gmail accounts, without verification, updates, or accountability.
Key statistics include:
– 26% of extensions are side-loaded
– 54% are published from Gmail accounts
– 51% have not been updated in over a year
– 6% of GenAI-related extensions are classified as malicious
This is no longer about productivity. It's an unmanaged software supply chain embedded at every endpoint.
Identity governance ends at the IdP. The risk begins at the browser.
The report finds that over two-thirds of logins are made outside of SSO and nearly half use personal credentials, making it impossible for security teams to know who is accessing what or from where.
Key findings include:
– 68% of corporate logins are made without SSO
– 43% of SaaS logins use personal accounts
– 26% of users reuse passwords across multiple accounts
– 8% of browser extensions have access to user identities or cookies
See also: OpenAI: Updates coming to AI-browser ChatGPT Atlas

Attacks like Scattered Spider have proven it: browser session tokens, not passwords, are now the main target.
