HomeSecurityNew browser security report reveals emerging threats to businesses

New browser security report reveals emerging threats to businesses

According to the new Browser Security Report 2025, security leaders are finding that the risks associated with SaaS and AI converge at a single point: the user’s browser. However, traditional controls like DLP, EDR, and SSE still operate one layer below.

See also: Firefox: New extensions must declare data collection practices

browser
New browser security report reveals emerging threats to businesses

What’s emerging isn’t just a blind spot. It’s a parallel threat landscape: unmanaged extensions that act like supply chain implants, GenAI tools accessed through personal accounts, sensitive data copied/pasted directly into prompt fields, and sessions that bypass SSO entirely.

This article analyzes the report's key findings and what they reveal about the changing audit focus on enterprise security.

GenAI is now the leading data extraction channel

The rise of GenAI in business workflows has created a huge governance gap. Nearly half of employees use GenAI tools, but most do so through unmanaged accounts, outside of IT visibility.

Key statistics from the report include:

– 77% of employees paste data into GenAI prompts
– 82% of these pastes come from personal accounts
– 40% of uploaded files contain PII or PCI
– GenAI accounts for 32% of all corporate-to-personal data traffic

Traditional DLP tools were not designed for this. The browser has become the dominant channel for copy/paste data extraction, without monitoring and without policies.

AI browsers are an emerging threat surface

Another emerging browser-based threat surface is 'agentic' AI browsers, which combine traditional browser security risks with new concerns about the use of AI.

AI browsers like OpenAI’s Atlas, Arc Search, and Perplexity Browser are redefining how users interact with the web, merging search, conversation, and browsing into a single intelligent experience. These browsers embed large language models directly into the browsing layer, allowing them to read, summarize, and reason on any page or tab in real time. For users, this means seamless productivity and content-based assistance. But for businesses, this represents a new and largely unmonitored attack surface: an “always-on collaborator” that silently sees and processes whatever an employee can see, without enforcing policies or visibility into what is shared with the cloud.

See also: AI browsers abused by malicious AI sidebar extensions

New browser security report reveals emerging threats to businesses
New browser security report reveals emerging threats to businesses

The risks are significant and multifaceted: session memory leaks expose sensitive data through AI personalization, invisible “auto-prompting” sends page content to third-party models, and shared cookies blur identity boundaries, allowing for potential takeovers. Without enterprise-level protections, these AI browsers essentially bypass traditional DLP, SSE, and browser security tools, creating an invisible, fileless path to data extraction. As organizations adopt GenAI and SaaS workflows, understanding and addressing this emerging blind spot is critical to preventing the next generation of data leaks and identity breaches.

Browser Extensions: The Most Widespread and Least Controlled Supply Chain

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

99% of business users have at least one extension installed. Over half grant high or critical permissions. Many are either sideloaded or published from Gmail accounts, without verification, updates, or accountability.

Key statistics include:

– 26% of extensions are side-loaded
– 54% are published from Gmail accounts
– 51% have not been updated in over a year
– 6% of GenAI-related extensions are classified as malicious

This is no longer about productivity. It's an unmanaged software supply chain embedded at every endpoint.

Identity governance ends at the IdP. The risk begins at the browser.

The report finds that over two-thirds of logins are made outside of SSO and nearly half use personal credentials, making it impossible for security teams to know who is accessing what or from where.

Key findings include:

– 68% of corporate logins are made without SSO
– 43% of SaaS logins use personal accounts
– 26% of users reuse passwords across multiple accounts
– 8% of browser extensions have access to user identities or cookies

See also: OpenAI: Updates coming to AI-browser ChatGPT Atlas

New browser security report reveals emerging threats to businesses
New browser security report reveals emerging threats to businesses

Attacks like Scattered Spider have proven it: browser session tokens, not passwords, are now the main target.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS