Friday, 29 August 2025
30.3 C
Singapore
36.4 C
Thailand
28.3 C
Indonesia
27.6 C
Philippines

QR codes could bypass browser security tool: Here’s how

Learn how QR codes could bypass browser isolation security, allowing malware communication despite sandboxing. Find out the risks and limits.

Cybersecurity experts have uncovered a surprising new method to bypass an essential browser security feature, even when advanced measures protect the browser. Researchers at Mandiant have demonstrated how QR codes can be exploited to enable malware to communicate with its command-and-control (C2) servers, even when a browser operates in an isolated or sandboxed environment.

What is browser isolation?

Browser isolation is a modern cybersecurity method that safeguards users from web-borne threats. Instead of allowing code and scripts to execute directly on your device, your browser communicates with a remote browser located in a cloud environment or virtual machine. You only receive a visual representation of the web page while all code and commands are processed on the remote system.

This approach effectively creates a barrier between your device and malicious websites, functioning like browsing through the lens of a camera. While this has been a significant step in preventing cyberattacks, the new findings suggest that even this advanced method is not foolproof.

The loophole: How QR codes play a role

Mandiant researchers have discovered a way for C2 servers to interact with malware on an infected device, even when browser isolation is active. The key lies in QR codes. When malware is present on a device, it can analyse the pixels rendered on the screen. If these pixels form a QR code, the malware can decode and use the information to execute further actions.

Mandiant demonstrated this vulnerability using the latest version of Google Chrome to prove the concept. They employed Cobalt Strike’s External C2 feature, a popular penetration testing tool, to showcase how the malware could receive instructions via QR codes.

Limitations of this method

Despite its potential, this technique has significant limitations. QR codes can only transmit a small amount of data—up to 2,189 bytes. Additionally, the process suffers from a latency of about five seconds, making it unsuitable for transmitting large payloads or supporting complex actions like SOCKS proxying.

Further security measures, such as URL scanning or data loss prevention systems, could render this method ineffective. These tools can detect unusual activity or block QR code data streams before damage is done.

While this method may seem impractical for large-scale attacks, it could still be used in targeted, destructive malware campaigns. As a result, IT teams are being urged to remain vigilant. Special attention should be given to monitoring the flow of traffic, especially from headless browsers operating in automation mode, which attackers commonly use to exploit vulnerabilities.

This discovery underscores the evolving nature of cyber threats and highlights the need for continuous advancements in security measures.

Hot this week

Asus subsidiary develops supercomputer to expand Taiwan’s computing power

Asus subsidiary Taiwan AI Cloud is building a Tainan-based supercomputer powered by Nvidia chips to boost Taiwan’s computing capacity by 50%.

Pan-United expands with AI-powered operations management system

Pan-United expands its AI-powered AiR Digital system to transform concrete and logistics operations across Asia-Pacific.

Belkin introduces first Qi2.2 chargers with 25W wireless charging speeds

Belkin launches its first Qi2.2-certified chargers, offering 25W wireless charging speeds with three models designed for both home and travel use.

ASUS ROG launches Matrix GeForce RTX 5090 30th anniversary edition

ASUS ROG celebrates 30 years of graphics cards with the Matrix GeForce RTX 5090, offering 800W power, advanced cooling, and limited availability.

Zoho showcases AI-powered business solutions at Zoholics Hong Kong

Zoho unveils AI-powered solutions including Zia LLM, Zia Hubs, and enhanced CRM at Zoholics Hong Kong to support business growth.

ChatGPT could be influencing the way people speak

A study suggests ChatGPT and similar AI tools are influencing spoken language, with AI buzzwords increasingly appearing in daily conversations.

Thinking Machines partners with OpenAI to accelerate AI adoption in Asia Pacific

Thinking Machines partners with OpenAI to expand enterprise AI adoption across Asia Pacific with training, app design, and leadership programmes.

100 women in tech power Singapore’s digital future as nation marks 60 years

Singapore honours 100 women leaders and 25 young achievers in the SG100WIT 2025 list, marking growing female impact in tech.

Synology introduces AI-powered Office Suite with new AI Console

Synology updates its Office Suite with AI-powered MailPlus, Office, and a new AI Console to boost productivity while ensuring data privacy.

Related Articles

Popular Categories