SquareX Warns Browser AI Agents Create Massive Security Risks
SquareX warns that Browser AI Agents in Chrome and Edge lack security awareness and are more susceptible to attacks than human employees.
Cybersecurity firm SquareX issued a security warning regarding the deployment of Browser AI Agents within Google Chrome and Microsoft Edge. The company states these tools expose organizations to a massive security risk because the agents lack the security awareness required to recognize suspicious URLs or excessive permission requests.
In proofs of concept, SquareX demonstrated that these agents are more susceptible to browser-based attacks than human employees, specifically showing how an agent could succumb to an OAuth attack to grant a malicious application full access to a user's email. Vivek Ramachandran of SquareX noted that the vulnerability stems from the fact that browsers cannot distinguish between actions performed by a human and those performed by an automation workflow, allowing agents to operate with the same high-level privileges as the user.
To mitigate these threats, SquareX recommends that enterprises implement browser-native guardrails and Browser Detection and Response tools. The firm advises individual users to enable the highest level of browser protection, such as Google's Enhanced Safe Browsing. These warnings come as research firm Gardener estimates that 15% of daily workflows will be completed by Browser AI Agents by 2028.