browser-security
Safeguard articles tagged "browser-security" — guides, analysis, and best practices for software supply chain and application security.
15 articles
Eight More Chromium Bugs Confirmed Exploited, Beyond V8
V8, Dawn, Skia, ANGLE, and Chromium's CSS engine each produced confirmed-exploited vulnerabilities — ten total this year across five distinct browser subsystems.
Two Chrome V8 Vulnerabilities Confirmed Exploited Within Five Days
Two memory-safety bugs in Chrome's V8 engine — out-of-bounds write and type confusion — both confirmed exploited within V8's sandbox in early September 2026.
XS-Leaks explained: cross-site leak techniques and the defenses that stop them
XS-Leaks bypass the Same-Origin Policy without running a single line of attacker script — they read state through timing, frame counts, and error events instead.
Clickjacking: A Prevention Guide
Clickjacking tricks a user into clicking something different from what they see by layering an invisible frame over a decoy page. Here is how to block it.
CORS Misconfiguration: How to Prevent It
A too-generous CORS policy can let a malicious site read authenticated responses from your API. Reflecting the Origin with credentials is the classic mistake.
Content Security Policy (CSP) Explained (2026)
A Content Security Policy is your last line of defense against XSS. Here is how CSP works, why nonce-based strict policies beat allowlists, and how to deploy one without breaking your app.
WebAssembly Security Explained (2026)
WebAssembly runs untrusted code in a memory-isolated sandbox, but sandboxed is not the same as safe. Here is how the Wasm security model actually works and where it breaks.
oidc-client-ts: A Security Guide for Browser OIDC
oidc-client-ts is the maintained TypeScript library for adding OpenID Connect and OAuth2 to browser apps. Here is how to use it, and how to avoid the token-handling mistakes that undo its security.
CORS Headers Explained: How to Configure Them Without Opening Holes
CORS headers tell a browser which cross-origin requests to a resource are allowed. Get them right and you enable legitimate clients; get them wrong and you hand attackers a door.
Aikido vs Koi: device/browser protection comparison
Aikido Security and Koi Security solve different layers of risk. Heres how they compare on device/browser protection, and where Safeguard fits in.
FileSaver.js (file-saver): Package Review and Download Security
The file saver npm package still powers client-side downloads in millions of builds, but it has not shipped a release since 2020. Here is what that means for your dependency tree.
What Causes a Memory Leak in JavaScript (and How to Find One)
A memory leak in JavaScript happens when objects you no longer need stay reachable, so the garbage collector can never free them. Here is how they start and how to hunt them down.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.