Browser extensions leave enterprises open to attack
Summary
A new report from LayerX Security highlights that browser extensions pose a significant security risk to enterprises. The study shows that 99% of enterprise users have at least one extension installed, with over half having more than ten. Nearly all users have installed extensions with high or critical permissions, granting access to sensitive data like cookies and passwords. GenAI-enabled extensions pose an even greater risk, with 58% having high permission levels, potentially bypassing corporate security controls. Over half of all extensions are published by anonymous or hobbyist developers, making it difficult to establish trust. The report suggests that browser extensions are often overlooked in security strategies, leaving enterprises vulnerable.