Site Isolation is Dead: How Site Isolation is Broken in Agentic Browsers and Extensions
Suyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin, Sanghyun Hong, Byoungyoung Lee, Sooel Son
Abstract
Site isolation is a cornerstone of modern web browser security. By strictly separating renderer processes that render untrusted webpages across different origins, it prevents malicious websites from accessing sensitive data belonging to other websites, thus underpinning the integrity of web services. However, as browsers increasingly integrate large language models (LLMs) and web agents to automate complex user tasks, these agents should often perform LLM-driven operations across isolation boundaries, thereby introducing new security risks.
Despite this shift, no previous studies have investigated how agentic browsers implement security mechanisms to protect LLM-driven agent operations from untrusted web content. In this work, we analyze the security designs of two open-source agentic browsers and seven agentic extensions, identifying a common architectural pattern: privileged processes manage user prompts and agent operations, while untrusted renderer processes are isolated, with inter-process communication (IPC) channels serving as their bridge. Building on this observation, we present two novel end-to-end attacks that exploit these IPC channels to perform (1) malicious prompt injections and (2) LLM-related data exfiltration. These attacks allow adversaries to interact with other websites or access sensitive user data through web agents, which have been considered challenging under strict site isolation. Our evaluation shows that all tested agentic browsers and extensions are vulnerable to these attacks, revealing that existing implementations often fail to properly account for IPC channels. We conclude with actionable defense guidelines for strengthening site isolation in agentic browsers and extensions. To the best of our knowledge, our work presents the first systematic study of the (in)security of site isolation in agentic browsers and extensions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4600afee-3c99-4092-b863-822706a2eb63Builds on22
- WebArena: A Realistic Web Environment for Building Autonomous AgentsShuyan Zhou, Frank F. Xu, Hao Zhu, Xuhui Zhou et al.ICLR 2024 · 1,197 citations
- AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language ModelsXiaogeng Liu, Nan Xu, Muhao Chen, Chaowei XiaoICLR 2024 · 722 citations
- SneakyPrompt: Jailbreaking Text-to-image Generative ModelsYuchen Yang, Bo Hui, Haolin Yuan, Neil Gong et al.S&P 2024 · 188 citations
- Detecting and Characterizing Lateral Phishing at ScaleGrant Ho, Asaf Cidon, Lior Gavish, Marco Schweighauser et al.USENIX Security 2019 · 113 citations
- Site Isolation: Process Separation for Web Sites within the BrowserCharles Reis, Alexander Moshchuk, Nasko OskovUSENIX Security 2019 · 105 citations
Related papers
- Are your Sites Truly Isolated? Automatically Detecting Logic Bugs in Site Isolation ImplementationsJan Drescher, David Klein, Martin JohnsNDSS 2026
- Isolated and Exhausted: Attacking Operating Systems via Site Isolation in the BrowserMatthias Gierlings, Marcus Brinkmann, Jörg SchwenkUSENIX Security 2023
- AgentBreaker: Evaluating Context-Aware Indirect Prompt Injection Risks in Modern Web AgentsYongbi Son, Changoo Lee, Dongwon Shin, Byoungyoung Lee et al.ISSTA 2026
- DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM AgentsHao Li, Xiaogeng Liu, Hung-Chun Chiu, Dianqi Li et al.NeurIPS 2025 · 76 citations
- MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection AttacksGeorgios Syros, Evan Rose, Brian Grinstead, Christoph Kerschbaumer et al.USENIX Security 2026 · 18 citations
