
Your browser is your new endpoint—and it’s vulnerable. In this episode, I speak with Audrey Adeline, Security Researcher at SquareX and co-author of the Browser Security Field Manual. Audrey walks us through why browser security is a rising concern, how current architectures fall short, and what her research team is doing to uncover novel browser-based threats.
We talk about her unconventional journey from VC to cyber researcher, the process of writing the field manual, and how SquareX tackles browser threats with tools far beyond Chrome’s own protections.
We also dive into:
Real-world attacks like polymorphic extensions and malicious OAuth apps
How even trusted extensions can be weaponized
What “MV3 compliant” really means (and doesn’t)
Why architectural flaws are harder to fix than software bugs
How SquareX uses AI for extension behavior analysis
Her take on impactful research and communication in the security field
This is a rare deep-dive into browser-native risks from someone at the frontier of browser security.