Browser Extensions, AI Browsers, and the Expanding Enterprise Attack Surface
At our recent Cyber Security Summit hosted by the Executive Leaders Network, Jeff Enis, Systems Engineer at LayerX Security, explored how modern browsers, extensions, and AI-enabled tools are reshaping the enterprise attack surface.
With nearly three decades of experience across network security, host security, application security, cloud security, virtualisation security, and security event management, Enis outlined a growing challenge facing organisations: the rapid expansion of browser-based risks that operate beyond traditional security controls.
The session examined the increasing use of browser extensions, the rise of AI-enabled browsers, and the difficulties security teams face in maintaining visibility and governance over these technologies.
Browser Extensions Are Everywhere in the Enterprise
Browser extensions are now deeply embedded in enterprise environments. They help users complete everyday tasks such as productivity enhancements, automation, integrations, and workflow improvements.
However, according to Enis, many organisations lack a clear inventory of extensions installed across their environments.
In some cases, security teams discover thousands of extensions deployed throughout their workforce. Even organisations that track extensions often only have partial visibility.
A recent example shared during the session highlighted a customer that had over 3,000 browser extensions installed across its enterprise environment. While this organisation had some awareness, many others have little to no visibility into:
- Which extensions are installed.
- What permissions those extensions request.
- Whether those extensions are secure or vulnerable.
This lack of oversight creates significant risk.
Browser extensions often request access to sensitive data, browsing activity, and application content. If left unmanaged, they can become a pathway for data exposure or unauthorised monitoring of user behaviour.
The Hidden Risk: Extensions Change Over Time
One of the most overlooked security concerns with browser extensions is that their behaviour can evolve after installation.
An extension that initially appears harmless may later request additional permissions through updates.
These updates may introduce capabilities such as:
- Screen recording.
- Access to browsing activity.
- Data collection from web pages.
- User behaviour monitoring.
Ownership of extensions can also change. Developers may sell popular extensions after gaining large user bases, potentially transferring control to new parties with different intentions.
Enis described a scenario where an extension gains millions of downloads while performing a legitimate function. After widespread adoption, developers could update the extension to request broader permissions, potentially exposing large volumes of user data.
This highlights a critical point: security decisions cannot rely solely on the original version of an extension. Continuous monitoring is required.
AI Browsers Are Introducing New Risks
Alongside extensions, the session also explored the rapid adoption of AI-enabled browsers and embedded assistants.
Major browsers such as Chrome and Microsoft Edge are increasingly integrating AI capabilities directly into the user experience. These capabilities typically appear in the form of:
- AI side panels.
- Browser-based assistants.
- Copilot-style features.
- Automated research tools.
These assistants can perform tasks on behalf of users, including searching for information, completing workflows, or interacting with external services.
In some cases, AI agents can even execute complex actions such as:
- Booking travel.
- Purchasing products.
- Conducting online negotiations.
While these capabilities may improve efficiency, they introduce new attack vectors.
Prompt Injection and AI Manipulation
A particularly concerning risk highlighted in the session is prompt injection.
Prompt injection occurs when an AI agent receives hidden instructions from a website or external source that alter its intended behaviour.
For example:
- A user asks an AI assistant to perform research online.
- The assistant visits a website during the task.
- The website injects hidden instructions into the interaction.
- The AI agent alters its behaviour without the user’s knowledge.
In some scenarios, the AI agent could expose sensitive information, access internal systems, or carry out unintended actions.
This introduces a new layer of risk because the AI is effectively acting on behalf of the user inside the browser environment.
Security Gaps in User-Side Activity
Another challenge discussed in the session involves data movement that bypasses traditional network controls.
Many security tools focus on monitoring network traffic, but not all data activity travels across the network in ways these tools can detect.
A simple example involves clipboard activity.
A user could:
- Copy sensitive information from a corporate application such as SharePoint
- Paste the information into a personal Gmail account
Because this activity occurs within the user interface and clipboard, no network traffic may be generated that traditional security tools can inspect.
This creates a blind spot where sensitive data can move between systems without triggering alerts.
Enis described this risk as occurring within the “ten most dangerous inches in IT” — the space between the user and the keyboard.
Moving Beyond Binary Security Decisions
Many organisations initially respond to emerging technologies like AI by restricting access entirely.
However, blocking tools such as large language models (LLMs) may conflict with business objectives, particularly as organisations pursue productivity improvements through AI adoption.
According to Enis, the challenge is finding a balance between security and enablement.
Instead of choosing between fully allowing or fully blocking AI tools, organisations can implement granular policies that control how those tools are used.
Examples of nuanced policies include:
- Allowing ChatGPT access but blocking uploads of sensitive documents.
- Preventing the sharing of API keys or tokens with external AI systems.
- Restricting data copied from corporate applications into personal services.
This approach enables productivity benefits while reducing the risk of data exposure.
Visibility Is the First Step
When asked what executives should focus on first, Enis emphasised the importance of understanding the current environment.
Before organisations can implement effective controls, they must answer several key questions:
- How many browser extensions exist across the organisation?
- Which of those extensions include AI capabilities?
- Which large language models are employees accessing?
- Are AI agents or autonomous browser tools being used?
- What permissions do installed extensions have?
- Are extensions accessing cookies, browsing behaviour, or sensitive data?
Many organisations cannot currently provide clear answers to these questions.
Without this visibility, security teams may struggle to evaluate risks or implement meaningful policies.
Managing the Expanding Browser Threat Surface
As browser-based tools continue to evolve, the enterprise attack surface will increasingly shift toward user interaction layers rather than traditional infrastructure.
Extensions, AI assistants, and browser automation tools are enabling new workflows, but they also introduce complex security challenges.
To manage this landscape effectively, organisations must focus on:
- Gaining visibility into browser usage and extensions
- Monitoring permission changes and extension updates
- Understanding how employees interact with AI systems
- Implementing policies that govern data movement within the browser
Rather than treating each new AI tool as a separate problem, Enis recommended adopting platform-level approaches that manage browsers, extensions, and AI interactions together.
Key Takeaways
- Browser extensions are widely deployed in enterprises, often without full visibility.
- Extensions can change permissions and ownership after installation, increasing risk.
- AI-enabled browsers and assistants introduce new attack surfaces.
- Prompt injection attacks can manipulate AI agents into unintended actions.
- Clipboard-based data movement can bypass traditional network security controls.
- Organisations should implement granular policies rather than blocking AI tools entirely.
- Security teams must first gain visibility into browser extensions, AI usage, and user activity.
Frequently Asked Questions
Why are browser extensions considered a security risk for organisations?
Browser extensions can request permissions that allow them to access browsing activity, webpage data, cookies, and other sensitive information. Many organisations do not maintain a full inventory of installed extensions, making it difficult to monitor their behaviour or identify risks.
In addition, extensions can change over time through updates, which may introduce new permissions or functionality.
Can legitimate browser extensions become malicious?
Yes. An extension may initially perform a legitimate function but later become risky due to updates or changes in ownership.
For example, developers might release a useful extension that gains millions of downloads before introducing updates that request broader permissions, potentially exposing user data.
What are AI browsers and how do they affect cybersecurity?
AI browsers integrate artificial intelligence features directly into the browsing experience. These features often appear as assistants, side panels, or automated agents that help users complete tasks online.
While these tools may improve efficiency, they also introduce new security concerns because AI agents can interact with websites, process data, and perform actions on behalf of users.
What is prompt injection in AI systems?
Prompt injection is a technique used to manipulate AI systems by inserting hidden instructions into the content they process.
For example, if an AI assistant visits a webpage during research, that webpage may include instructions designed to alter the AI’s behaviour. In some situations, this could cause the AI to reveal sensitive information or perform unintended actions.
Why do traditional security tools struggle to detect some browser-based risks?
Traditional security tools primarily monitor network traffic. However, some user actions — such as copying and pasting data between applications — occur entirely within the user interface and do not generate detectable network traffic.
This means sensitive information may move between systems without being identified by standard network security controls.
Watch the Full Session On-Demand
To explore the full discussion and learn more about browser security in the modern age, watch the complete session here:
CyberSecure Online Summit | Virtual Event for Cybersecurity Leaders
#browsersecurity #enterprisebrowsersecurity #browserextensionsrisk #AIbrowsers #AIenabledbrowsers #enterpriseattacksurface #cybersecurity #browserbasedthreats #browserextensionvulnerabilities #enterprisesecurity #AIsecurityrisks
Recent Articles
Unlock the Potential of Your SaaS Data: Secure Data Strategies for 2024
The eBook "SaaS Success: Secure Data Strategies for…