logo

Attackers Can Use QR Codes to Bypass Browser Isolation

ID: 0155e598-8936-5bef-a87c-b9dd7bb0668c

STIX ID: report--0155e598-8936-5bef-a87c-b9dd7bb0668c

Feed Name: Dark Reading

Threat Score
30/100

Date Published: 2024-12-09

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Mandiant researchers published a proof-of-concept showing attackers can bypass remote/on-premises/local browser isolation by returning pages that render machine-readable QR codes; a local implant running a headless browser screenshots and decodes the QR to receive C2 commands and exfiltrate output via URL parameters. The report details the attack sequence, technical constraints (QR data-size limits, multi-second latency, and unaddressed isolation controls like domain reputation or DLP), and recommends continuing to use browser isolation alongside monitoring and automated browser protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.