The browser serves as the most attacked surface in the enterprise. It has been the most attacked surface for two years, and the margin keeps growing. The risk has migrated from phishing links to extensions, to session tokens, to the data residency in the cloud profiles the browser keeps for the user. The attacker has noticed what the defender has not always noticed, which is that the browser now holds the keys to most of the enterprise.
The browser in 2026 runs as the operating system the user actually uses. The operating system underneath it sits as the substrate, with the browser the place where the work, the data, the credentials, the sessions all live. That change of role has not yet been priced into most enterprise security programs.
Where the risk lives now
Four surfaces, in roughly that order of how often each one shows up in a breach postmortem. The first runs as the extension, where the user installs a browser extension from the official store, the extension has been compromised (or the developer has been compromised), the extension exfiltrates the session tokens, the credentials, the clipboard. The second runs as the session token, where the attacker steals the session token from the cookie, the local storage, the browser profile, the attacker replays the session without needing the password, the MFA, the second factor. The third runs as the cloud profile, where the browser keeps the cloud session (the Google, the Microsoft, the AWS) alive in the background, the attacker who compromises the browser profile gets the cloud access without reauthenticating. The fourth runs as the download, where the user downloads a file the browser marks as safe, the file contains the macro, the script, the loader, the breach starts.
What the vendors added
Three things, in roughly that order of how useful each one runs in practice. The first runs as the enterprise extension allow list, where the major browsers (the Chrome, the Edge, the Firefox) now let the enterprise control which extensions the user can install, the enterprise can block the extensions that the security team has not approved. The second runs as the session token binding, where the browser binds the session token to the device, the token cannot be replayed from a different device, the attacker who steals the token still needs the device. The third runs as the download reputation, where the browser checks the download against the cloud reputation list, the browser blocks the file before the user can open it, the warning shows up before the breach starts.
What the defender should do
Three moves if you are the defender who treats the browser as the new perimeter. Lock the extensions, because the extension runs as the easiest surface for the attacker to compromise, the enterprise extension allow list closes the surface, the user gets the productivity without the risk. Enforce the session token binding, because the session token theft sits as the dominant identity attack in 2026, the token binding breaks the replay, the attacker who steals the token cannot use it from another device. Audit the cloud profiles quarterly, because the cloud profile is where the persistent access lives, the audit finds the stale sessions, the orphaned tokens, the over privileged applications. The enterprise that locks the extensions, enforces the token binding, and audits the profiles quarterly serves as the enterprise that treats the browser as the new perimeter.

The bottom line
The browser in 2026 serves as the operating system the user actually uses, and the attacker has noticed. Lock the extensions, bind the tokens, audit the cloud profiles. The defender who treats the browser as the new perimeter holds the line. The defender who treats the browser as a productivity tool loses the line.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



