By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Marketing In Asia
  • Marketing
    • Viral
    • Expert Opinions
    • News & Trends
    • Research
    • Market Podcasts
    • Market Videos
    Marketing
    This category deals with best news and updates on marketing and branding news and events.
    Show More
    Top News
    Sangeeta Mudnal
    How conversational commerce benefits marketers
    8 months ago
    Andrew Monu, VP of Marketing, LinkedIn
    Marketing in Asia Presents an Exclusive Interview with Andrew Monu, VP of Marketing, LinkedIn
    8 months ago
    Ankita Thakur
    Marketing in Asia Presents an Exclusive Interview with Ankita Thakur, Group Head of Marketing, MoneyHero Group
    8 months ago
    Latest News
    Marketing in Asia Presents an Exclusive Interview with Cris Tan, Associate Director, Publisher Development (SEA)
    8 months ago
    Time for ASEAN to Rethink a Single Currency Amid Global Trade Tensions
    8 months ago
    Marketing in Asia Presents an Exclusive Interview with Carine Chin, Head of Corporate Marketing, Etiqa Insurance Singapore
    8 months ago
    Marketing in Asia Presents an Exclusive Interview with April Tayson, Regional VP INSEAU at Adjust
    8 months ago
  • Startup
    • News from Startup world
    • Startup Stories
    • Trends and Opinions
    • Startup Podcasts
    • Startup Videos
    Startup
    News and articles from startup and venture investment world
    Show More
    Top News
    Japan’s Evolving Booze Culture: A Market in Transformation
    Japan’s Evolving Booze Culture: A Market in Transformation
    1 year ago
    text
    Safe Space™ announces partnership with National Healthcare Group as it continues to boost employee support and wellbeing
    1 year ago
    Sakshi Kalani Founder & CEO of Savy Click and Jaipur Unfolded
    AI-Powered Analytics: Sakshi Kalani on Influencer Marketing in 2025
    1 year ago
    Latest News
    Byron J. Fernandez: Minimize the stress of business crises with strong CX
    1 year ago
    Vedant Mahajan Acquires Stake in Flite: Transforming Event Technology with Innovation
    1 year ago
    Navigating the Digital Economy and Tax Challenges for SMEs
    1 year ago
    sehatUP Launches India’s First Integrated Digital Health Clinic, Pioneering Holistic Healthcare
    1 year ago
  • Business
    • Feature Stories
    • News
    • Business Podcasts
    • Business Videos
    Business
    News and press releases from business world of Asia
    Show More
    Top News
    Asean countries
    Time for ASEAN to Rethink a Single Currency Amid Global Trade Tensions
    8 months ago
    Carine Chin
    Marketing in Asia Presents an Exclusive Interview with Carine Chin, Head of Corporate Marketing, Etiqa Insurance Singapore
    8 months ago
    April Tayson, Regional VP INSEAU at Adjust
    Marketing in Asia Presents an Exclusive Interview with April Tayson, Regional VP INSEAU at Adjust
    8 months ago
    Latest News
    Exclusive Interview : Marketing In Asia with April Tayson
    3 months ago
    Exclusive Interview: Adeline Lim, CMO & Head of Commercial Excellence at Menarini Asia-Pacific, Shares Insights with Marketing in Asia
    4 months ago
    Exclusive Interview: Twilio’s Sam Richardson Talks Brand Communications with Marketing in Asia
    4 months ago
    Marketing in Asia Presents an Exclusive Interview with Cris Tan, Associate Director, Publisher Development (SEA)
    8 months ago
  • Society
    • Inspiration
    • Destinations & Travel
    • Food & Gourmet
    • People
    • Young Voices
    • Society Videos
    • Society Podcasts
    Society
    News and articles from and for societies around us
    Show More
    Top News
    Smashers Sports Acquires Delhi Franchise of WPBL: A Game-Changer in India’s Sports Entertainment
    Smashers Sports Acquires Delhi Franchise of WPBL: A Game-Changer in India’s Sports Entertainment
    1 year ago
    Resorts World Cruises Sets Sail from Dubai with New Luxury Gulf Voyages
    Resorts World Cruises Sets Sail from Dubai with New Luxury Gulf Voyages
    1 year ago
    Australia luxury property
    Australia’s Luxury Real Estate Market Soars as Affluent Buyers Seek Waterfront Dreams
    1 year ago
    Latest News
    From Taboo to Triumph: How Malaysians Are Transforming Their Intimate Health Journey
    10 months ago
    Top 5 Misconceptions About Antibiotics Malaysians Need to Stop Believing
    10 months ago
    Eagle Eye Reveals Impact of Loyalty Programs on APAC Retailers
    10 months ago
    Elevate Your Haircare in 2025 with Jung Beauty’s Luxurious Camellia Edition Treatment
    1 year ago
  • Press Release
  • Awards
    • MIA Impact Circle Stellar CxO 2023 Malaysia
    • MIA Impact Circle Stellar CxO 2023 India
    • MIA Impact Circle Stellar CxO 2023 Philippines
    • Australian Women in Business Excellence Awards
    • MIA Impact Circle Stellar CxO 2024 Singapore
    • Mia Impact Circle Stellar Cxo 2024 Hongkong Award 
    • Mia Impact Circle Stellar Cxo 2024 Indonesia Award 
Search
Technology
  • Hot
  • Trending
  • Editor’s Choice
  • NSFW
  • Reactions
  • Authors
  • Viral on Internet
Other Pages
  • My Bookmarks
  • Customize Interests
  • About Marketing In Asia
  • Business Register & Login
  • Web Stories
  • Videos
  • Disclaimer
  • Terms of Service
  • Privacy Policy
© 2024 Marketing In Asia Sdn Bhd. All Rights Reserved.
Reading: SquareX’s Year of Browser Bugs Exposes Critical Vulnerabilities Across Enterprise Browsing
Share
Sign In
Notification Show More
Latest News
Upali Dasgupta
Meltwater’s Upali Dasgupta: In 2026, AI will reshape the customer journey 
Press Release
Coca-Cola
Marketing in Asia Interviews Foodmarks Singapore: Exclusive Insights
Press Release
Joh Go
Dataiku Appoints Jo Goh as Area Vice President of Asia Pacific and Japan Partnerships
Press Release
Susan Ho
FGS Global Appoints Susan Ho as Asia Chair to Lead Regional Growth and Strategic Advisor
Press Release
James Nicholas
INVNT® Appoints James Nicholas Kinney as Global Chief AI Officer, Advancing a New Era Of AI-Powered Brand Storytelling  
Press Release
Aa
Marketing In Asia
Aa
  • Hot
  • Trending
  • Editor’s Choice
  • NSFW
  • Reactions
  • Authors
  • Viral on Internet
  • My Bookmarks
  • Customize Interests
  • About Marketing In Asia
  • Business Register & Login
  • Startup Register & Login
Search
  • Marketing
    • Viral
    • Expert Opinions
    • News & Trends
    • Research
    • Market Podcasts
    • Market Videos
  • Startup
    • News from Startup world
    • Startup Stories
    • Trends and Opinions
    • Startup Podcasts
    • Startup Videos
  • Business
    • Feature Stories
    • News
    • Business Podcasts
    • Business Videos
  • Society
    • Inspiration
    • Destinations & Travel
    • Food & Gourmet
    • People
    • Young Voices
    • Society Videos
    • Society Podcasts
  • Press Release
  • Awards
    • MIA Impact Circle Stellar CxO 2023 Malaysia
    • MIA Impact Circle Stellar CxO 2023 India
    • MIA Impact Circle Stellar CxO 2023 Philippines
    • Australian Women in Business Excellence Awards
    • MIA Impact Circle Stellar CxO 2024 Singapore
    • Mia Impact Circle Stellar Cxo 2024 Hongkong Award 
    • Mia Impact Circle Stellar Cxo 2024 Indonesia Award 
Have an existing account? Sign In
Follow US
© 2023 Marketing In Asia Sdn Bhd. All Rights Reserved.
Marketing In Asia > Blog > Press Release > SquareX’s Year of Browser Bugs Exposes Critical Vulnerabilities Across Enterprise Browsing
Press Release

SquareX’s Year of Browser Bugs Exposes Critical Vulnerabilities Across Enterprise Browsing

profile
Last updated: 2025/12/15 at 12:53 PM
MIA Editor
Share
5 Min Read
SquareX
SHARE

 SquareX, the pioneer in Browser Detection and Response (BDR), released a comprehensive recap of its Year of Browser Bugs (YOBB) project, a year-long commitment to research and expose critical architectural vulnerabilities in the browser.

Over the past decade, the browser has become the new endpoint—the primary gateway through which employees access SaaS apps, interact with sensitive data, and use the internet. The modern browser has also evolved significantly, with many capabilities that support complex web apps that parallel the performance of native apps. As with all new technologies, the very same features are also being used by malicious actors to exploit users, exploiting a massive security gap left by traditional solutions that primarily focus on endpoints and networks. Compounded with the release of AI Browsers, the browser has become the single most common initial access point for attackers. Yet, it remains to be poorly understood.

In the past 12 months, SquareX researchers released 11 research pieces, including major zero day vulnerabilities presented at DEF CON, BlackHat, RSA and BSides. These research pieces cover the gamut of browser-based threats, from polymorphic extensions, to Browser-Native Ransomware, to AI browser vulnerabilities.  

“When we launched YOBB earlier this year, SquareX has been seeing a lot of browser native vulnerabilities that are being used to exploit enterprises and users,” said Vivek Ramachandran, Founder of SquareX. “These disclosures demonstrate that architectural limitations across browsers, extensions, and emerging AI technologies are putting organizations at risk in ways traditional security solutions simply cannot address. This demonstrates the importance of security teams to keep up with the modern way of working, whether it is securing AI or the browser itself.”

Critical Key Findings Recap

Browser Extension Vulnerabilities

SquareX exposed fundamental flaws in how browser extensions operate and are monitored. Browser Syncjacking (January) demonstrated that malicious extensions can fully take over user profiles, the browser and devices with minimal permissions. Polymorphic Extensions (February) revealed how attackers can perfectly mimic legitimate extensions like password managers and crypto wallets to steal credentials. The Architectural Limitations of Browser DevTools (July) research showed that there is little that end users can do to inspect extension behaviors in the browser, leaving security teams exposed to extension security risks.  

AI Browser and Browser AI Agent Security

As AI-powered browsers gained enterprise adoption, SquareX continued to uncover critical vulnerabilities in AI Browsers. SquareX researchers revealed 79% of organizations deploy agentic workflows today. Unfortunately, Browser AI Agents (June), are trained to do tasks, not to be security aware, making them more vulnerable to attacks than human employees. Architectural Security Vulnerabilities of AI Browsers (September) exposed how attackers can exploit AI browsers to exfiltrate data, distribute malware and unauthorized access to users’ SaaS apps. The AI Browser Sidebar Spoofing Attack (October) demonstrated how malicious extensions can inject a pixel-perfect replication of AI sidebars, which provides false instructions that eventually lead to phishing, malicious file download and even device takeover. Most recently, SquareX researchers discovered a poorly documented MCP API in Comet (November) which allows its embedded extensions to execute arbitrary local commands, including known ransomware without explicit user permission.

Data Exfiltration and Identity Attacks

In August, SquareX made new research frontiers in browser-based data exfiltration and identity attacks at a DEF CON 33 talk titled Passkeys Pwned: Turning WebAuthn Against Itself, highlighting a passkey implementation flaw that allows unauthorized access to enterprise SaaS apps and resources via a malicious script/browser extension. At BSides SF 2025, our researchers also presented Data Splicing Attacks (April) — a set of data exfiltration techniques that bypass all Data Loss Protection (DLP) solutions listed by Gartner’s Magic Quadrant. Browser Native Ransomware (March) showed how ransomware attacks could be executed without any local files or process, by exploiting identity attacks in the browser, while the Fullscreen BitM Attack (May) demonstrated how a single click by the user, can trigger a full screen attacker-controlled browser window where victims unknowingly enter credentials while being fully monitored.

The complete Year of Browser Bugs report is a roundup of all the research that SquareX has conducted and is available for download here.

As the year comes to a close, SquareX’s commitment to browser security research intensifies and will not just stop here. SquareX is committed to continuously uncover emerging threats via its browser detection and response capabilities to help enterprises to stay ahead of attackers targeting the browser – the most exploited attack surface in modern enterprises.

Legal Disclaimer: The Editor provides this news content "as is," without any warranty of any kind. We disclaim all responsibility and liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. For any complaints or copyright concerns regarding this article, please contact the author mentioned above.

You Might Also Like

Meltwater’s Upali Dasgupta: In 2026, AI will reshape the customer journey 

Marketing in Asia Interviews Foodmarks Singapore: Exclusive Insights

Dataiku Appoints Jo Goh as Area Vice President of Asia Pacific and Japan Partnerships

FGS Global Appoints Susan Ho as Asia Chair to Lead Regional Growth and Strategic Advisor

INVNT® Appoints James Nicholas Kinney as Global Chief AI Officer, Advancing a New Era Of AI-Powered Brand Storytelling  

MIA
Get Latest Job Updates on Whatsapp and Telegram
SCIKEY Logo
Whatsapp
Telegram
TAGGED: insight, marketing, strategy

Sign Up For MIA Newsletter

Be keep up! Get the latest updates about the Marketing world delivered straight to your inbox.

    By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
    MIA Editor December 15, 2025 December 15, 2025
    Share This Article
    Facebook Twitter LinkedIn Email Copy Link Print
    Share
    What do you think?
    Love0
    Happy0
    Joy0
    Surprise0
    Sad0
    Angry0
    Cry0
    Previous Article Neeraj Khushwaha Exclusive Interview: Neeraj Kushwaha of Third i Shares Insights with Marketing In Asia
    Next Article Sean Fu Exclusive Interview: Sean Fu, Senior Vice President, Greater China at Global Payments, Shares Insights on Regional Growth with Marketing In Asia
    9.5k Followers Follow
    3.4k Followers Like
    1.1k Followers Follow
    214 Followers Follow
    208 Subscribers Subscribe

    Latest News

    Upali Dasgupta
    Meltwater’s Upali Dasgupta: In 2026, AI will reshape the customer journey 
    Press Release 2 days ago
    Coca-Cola
    Marketing in Asia Interviews Foodmarks Singapore: Exclusive Insights
    Press Release 2 days ago
    Joh Go
    Dataiku Appoints Jo Goh as Area Vice President of Asia Pacific and Japan Partnerships
    Press Release 2 days ago
    Susan Ho
    FGS Global Appoints Susan Ho as Asia Chair to Lead Regional Growth and Strategic Advisor
    Press Release 2 days ago

    PropertyGuru

    property guru

    You Might also Like

    Upali Dasgupta
    Press Release

    Meltwater’s Upali Dasgupta: In 2026, AI will reshape the customer journey 

    2 days ago
    Coca-Cola
    Press Release

    Marketing in Asia Interviews Foodmarks Singapore: Exclusive Insights

    2 days ago
    Joh Go
    Press Release

    Dataiku Appoints Jo Goh as Area Vice President of Asia Pacific and Japan Partnerships

    2 days ago
    Susan Ho
    Press Release

    FGS Global Appoints Susan Ho as Asia Chair to Lead Regional Growth and Strategic Advisor

    2 days ago
    //

    Get Asia to Notice You

    Quick Link

    • Contact
    • RSS Terms of Service
    • Policies & Standards
    • About Us
    • FAQ
    • Disclaimer
    • Terms Of Service
    • Privacy Policy

    Top Categories

    • Marketing
    • Startup
    • Feature Stories
    • News
    • People
    • Inspiration

    Sign Up for Our Newsletter

    Subscribe to our newsletter to get our newest articles instantly!

      Marketing In AsiaMarketing In Asia
      Follow US
      © 2024 Marketing In Asia. All Rights Reserved.
      • Disclaimer
      • Terms of Service
      • Privacy Policy