SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution
Palo Alto, California, Thu, Oct 9, 2025, CyberNewsWire
Palo Alto, California, Thu, Oct 9, 2025, CyberNewsWire
SquareX has released a report revealing significant vulnerabilities in AI Browsers, highlighting potential risks for enterprises. These vulnerabilities could be exploited by attackers to exfiltrate sensitive data, distribute malware, and gain unauthorized access to enterprise SaaS applications.
This disclosure coincides with recent announcements from companies like OpenAI, Microsoft, and Google regarding their AI browser initiatives. Given that Chrome and Edge account for 70% of the browser market share, it is crucial for organizations to address these emerging security challenges.
AI Browsers, designed to perform tasks, may be susceptible to manipulation by attackers, as they lack inherent security awareness. SquareX emphasizes the need for browser-native solutions to implement security measures, such as agentic identity and agentic Data Loss Prevention (DLP), to safeguard users.
In its technical blog , SquareX presents case studies demonstrating how AI Browsers like Comet were compromised. One case involved an OAuth attack, granting attackers full access to a victim's email and Google Drive.
This disclosure coincides with recent announcements from companies like OpenAI, Microsoft, and Google regarding their AI browser initiatives.
Another example involved the distribution of a malicious link through a calendar invite during task completion in a user's inbox. Additional scenarios included malware downloads and unauthorized emailing of sensitive files.
Existing security solutions, such as EDRs and SASE/SSE, have limited visibility into browser activities, making it challenging to distinguish between actions initiated by users and AI agents like Comet. Enterprises require solutions that can differentiate between agentic and user activities to apply appropriate security controls.
SquareX’s findings underscore the necessity for collaboration between enterprises, browser developers, and cybersecurity firms to develop robust security frameworks that protect against AI Browser vulnerabilities.
SquareX provides a browser extension that enhances security for any browser, including AI Browsers. Its Browser Detection and Response (BDR) solution helps organizations defend against browser-native threats, such as rogue AI agents and malicious extensions, while integrating seamlessly with existing consumer browsers.
Further information on SquareX’s research and innovations can be found at www.sqrx.com .
Based on reporting by Cyber Security News.
