3 MIN READ
The browser sits as the most attacked surface in the enterprise, and the margin keeps growing. Two years ago the answer was the phishing link. A year ago the answer was the extension. In Q3 2026 the answer is the session token, the cloud profile, the persistent sign-in, the piece of state the browser keeps so the user does not have to reauthenticate. They have noticed. The defender has not always noticed.
Chrome and Edge together cover most of the corporate installs. The security model they shipped with in 2010 has not been substantially revised. The browser holds the keys to most of what matters now, the data, the SaaS admin consoles, the email, the cloud provider, and most security programs still treat it as a productivity tool rather than the new operating system it has become.
Where the risk lives now
Four surfaces account for most of the breach postmortems. Extensions lead the list. A user installs something from the Chrome Web Store that looks legitimate, the developer account gets phished, the extension ships an update that exfiltrates session tokens, clipboard contents, and form data. The session token sits as the close second. A token in a cookie or in local storage, lifted through a renderer exploit or a malicious extension, replayed from somewhere else without ever needing the password, the MFA, or the second factor. The cloud profile is the third. The browser keeps the Google, Microsoft, or AWS session alive in the background. The compromise of the profile gives the cloud access without reauthenticating, and the audit trail looks like a normal user. Downloads round out the list. A file the browser marked as safe, opened by the user, containing the macro, the script, the loader that drops the rest of the chain.
What the vendors added
The big three browsers shipped useful controls over the last year. Chrome, Edge, and Firefox all added enterprise extension allow lists, with the platform org able to block any extension that has not been approved, and the user prompted instead of silently installed. Device bound session credentials are starting to land, with the token cryptographically tied to the device so a stolen token cannot be replayed from a different machine. Download reputation is now a default on the major browsers, with the file checked against the cloud reputation list before the user can open it, and the warning shown before the breach starts. None of these are silver bullets. The combination closes most of the practical gap.
What the defender should do
Lock the extensions first. The allow list is the single highest value control the security team has, because the extension sits as the easiest surface to compromise and the hardest for the user to evaluate. Productivity without the risk is achievable. The user gets the approved list, the platform org gets the audit log.
Enforce the device bound session credentials. The token theft pattern runs as the dominant identity attack in 2026, and the device binding breaks the replay. A token stolen from the laptop cannot be used from another machine, which collapses the economics of most of the token theft kits on the market.
Audit the cloud profiles quarterly. The cloud profile sits as where the persistent access lives, and the quarterly audit finds the stale sessions, the orphaned tokens, the over privileged applications. The audit is not glamorous. The audit is what stops the breach that landed six months ago and has been quietly exfiltrating ever since.

The bottom line
Lock the extensions, bind the tokens, audit the cloud profiles. The defender who treats the browser as the new perimeter holds the line. The one who treats the browser as a productivity tool loses it.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



