Site Isolation is Dead: How Site Isolation is Broken in Agentic Browsers and Extensions
Suyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin, Sanghyun Hong, Byoungyoung Lee, Sooel Son
摘要
Site isolation is a cornerstone of modern web browser security. By strictly separating renderer processes that render untrusted webpages across different origins, it prevents malicious websites from accessing sensitive data belonging to other websites, thus underpinning the integrity of web services. However, as browsers increasingly integrate large language models (LLMs) and web agents to automate complex user tasks, these agents should often perform LLM-driven operations across isolation boundaries, thereby introducing new security risks.
Despite this shift, no previous studies have investigated how agentic browsers implement security mechanisms to protect LLM-driven agent operations from untrusted web content. In this work, we analyze the security designs of two open-source agentic browsers and seven agentic extensions, identifying a common architectural pattern: privileged processes manage user prompts and agent operations, while untrusted renderer processes are isolated, with inter-process communication (IPC) channels serving as their bridge. Building on this observation, we present two novel end-to-end attacks that exploit these IPC channels to perform (1) malicious prompt injections and (2) LLM-related data exfiltration. These attacks allow adversaries to interact with other websites or access sensitive user data through web agents, which have been considered challenging under strict site isolation. Our evaluation shows that all tested agentic browsers and extensions are vulnerable to these attacks, revealing that existing implementations often fail to properly account for IPC channels. We conclude with actionable defense guidelines for strengthening site isolation in agentic browsers and extensions. To the best of our knowledge, our work presents the first systematic study of the (in)security of site isolation in agentic browsers and extensions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper22
- WebArena: A Realistic Web Environment for Building Autonomous AgentsShuyan Zhou, Frank F. Xu, Hao Zhu, Xuhui Zhou 等ICLR 2024 · 被引用 1,197 次
- AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language ModelsXiaogeng Liu, Nan Xu, Muhao Chen, Chaowei XiaoICLR 2024 · 被引用 722 次
- SneakyPrompt: Jailbreaking Text-to-image Generative ModelsYuchen Yang, Bo Hui, Haolin Yuan, Neil Gong 等S&P 2024 · 被引用 188 次
- Detecting and Characterizing Lateral Phishing at ScaleGrant Ho, Asaf Cidon, Lior Gavish, Marco Schweighauser 等USENIX Security 2019 · 被引用 113 次
- Site Isolation: Process Separation for Web Sites within the BrowserCharles Reis, Alexander Moshchuk, Nasko OskovUSENIX Security 2019 · 被引用 105 次
相关 Paper
- Are your Sites Truly Isolated? Automatically Detecting Logic Bugs in Site Isolation ImplementationsJan Drescher, David Klein, Martin JohnsNDSS 2026
- Isolated and Exhausted: Attacking Operating Systems via Site Isolation in the BrowserMatthias Gierlings, Marcus Brinkmann, Jörg SchwenkUSENIX Security 2023
- AgentBreaker: Evaluating Context-Aware Indirect Prompt Injection Risks in Modern Web AgentsYongbi Son, Changoo Lee, Dongwon Shin, Byoungyoung Lee 等ISSTA 2026
- DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM AgentsHao Li, Xiaogeng Liu, Hung-Chun Chiu, Dianqi Li 等NeurIPS 2025 · 被引用 76 次
- MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection AttacksGeorgios Syros, Evan Rose, Brian Grinstead, Christoph Kerschbaumer 等USENIX Security 2026 · 被引用 18 次
