Skip to main content
A browser agent executes code from every page it visits. Browser process isolation, network policy, and credential boundaries are therefore part of the product, not optional hardening. Updated October 9, 2026. Treat every website, redirect, download, extension, and page script as hostile input.

Use one disposable session boundary

Launch one isolated runtime per browsing session or tenant trust boundary. Give the session a fresh browser profile, writable temporary directory, unique network identity, hard timeout, and no inherited cookies. Do not share one Chrome process across unrelated tenants. Incognito contexts reduce state sharing but are not equivalent to a separate runtime boundary for hostile multi-tenant execution.

Preserve the browser sandbox

Playwright’s official guidance warns that its default root container disables Chromium’s sandbox and is not recommended for untrusted websites. Puppeteer’s official image documents a sandbox mode requiring SYS_ADMIN. Fargate restricts SYS_ADMIN and custom host-level seccomp behavior. That makes the exact secure Chromium sandbox configuration a design gate. Do not silently add --no-sandbox to make production start. Use a runtime that demonstrably supports the browser sandbox, or place the browser in a stronger microVM/VM boundary. Test the actual kernel, seccomp, user namespaces, image, and browser version.

Restrict network reachability

A URL allowlist is useful but incomplete. Enforce egress at the network layer:
  • deny instance metadata and link-local addresses,
  • deny VPC private ranges unless explicitly required,
  • validate every redirect and DNS result,
  • route public traffic through an egress proxy,
  • log destinations without sensitive query strings,
  • block unsupported protocols and raw socket access.

Protect credentials

Keep model credentials in the controller when possible. If the browser needs site credentials, scope them to one session and domain. Separate authenticated browsing from arbitrary open-web browsing. Downloads and clipboard content can exfiltrate secrets.

Bound browser behavior

Limit tabs, popups, downloads, total bytes, CPU, memory, session duration, idle duration, navigation time, and output. Upload selected screenshots or traces, then destroy the browser profile.

Frequently asked questions

Not automatically. The browser’s own sandbox must work, network reachability must be restricted, and tenant sessions need strong separation. Containers are one layer in the boundary, not the complete threat model.
Trusted automation can fit a Worker after testing. Hostile multi-tenant browsing needs disposable per-session execution and a verified browser sandbox, which is not a current first-class Springwinter resource.
The task may still reach metadata, private services, databases, or control-plane endpoints. A compromised page can make the browser request those targets unless egress policy blocks them.

Sources and further reading

Last modified on October 8, 2026