The OWASP Browser Security Project raises awareness, provides education, and establishes best practices for securing modern web browsers. Browsers now serve as the primary execution environment for most applications, and this project offers clear, actionable guidance for identifying, mitigating, and preventing browser-layer threats.
A comprehensive verification standard for browser security, following the model of OWASP's ASVS. Defines security requirements and verification levels for browser-based applications.
The top 10 browser security risks, providing a prioritized awareness document for developers, security professionals, and organizations.
A practical guide covering browser security topics in depth, including browser features, extensions, AI-enabled capabilities, and enterprise configuration.
We welcome contributions from the OWASP community and industry partners. See individual project directories for contribution guidelines, or open an issue to start a discussion.
This project is licensed under the terms described in LICENSE.md.
