Web Hack List

Preliminary research

Site Isolation is Dead: How Site Isolation is Broken in Agentic Browsers and Extensions

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Site isolation separates renderer processes per origin, but an agentic browser's whole purpose is to act across that boundary. Two open-source agentic browsers and seven agentic extensions share one architecture - privileged processes hold the prompts and agent operations, untrusted renderers are isolated, IPC bridges them - and two end-to-end attacks cross that IPC: prompt injection, and LLM data exfiltration.

Record

Researcher
Suyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin, Sanghyun Hong, Byoungyoung Lee and Sooel Son
Format
Whitepaper

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Suyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin, Sanghyun Hong, Byoungyoung Lee and Sooel Son, first published at the original source. Preserved copies are kept so the citation survives its host.