Modern Windows applications are quietly shipping with a built-in Chromium-based browser, WebView2, running inside trusted, signed processes such as Microsoft Teams, Outlook, and other enterprise software.
This talk shows how that design choice creates a powerful and largely unmonitored attack surface.
I demonstrate how this model can be abused in offensive operations, turning WebView2 into a vector for persistence, code execution, and enterprise account impersonation.
I show how feature flags and environment variables can be leveraged to manipulate the WebView2 runtime, enabling techniques such as DLL sideloading within legitimate applications. This allows arbitrary code execution inside trusted processes, supporting stealthy living-off-the-land persistence.
Building on this, I present methods to intercept and proxy HTTP/HTTPS traffic generated by WebView2-based applications. This enables the extraction of session tokens, cookies, and other sensitive artifacts, leading to realistic account takeover and impersonation scenarios, including access to platforms such as Office 365.
In addition to the offensive techniques, I provide a detailed analysis of the Indicators of Compromise (IOCs) generated throughout these attack chains. I highlight detection opportunities, discuss current visibility gaps in EDR solutions, and propose practical approaches for identifying and responding to this type of activity in real-world environments.
Presented at Red Team Village — DEF CON 2026