Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A website cannot normally take control of your entire browser or computer just by running JavaScript. The more precise risk is that a vulnerable site can be tricked into running an attacker’s code as part of that site. This attack, called cross-site scripting (XSS), can let the code interact with the site’s page and act with some of the authority available to its scripts.

What “take over your browser” means

In an XSS attack, a site handles attacker-influenced input unsafely and causes the browser to interpret it as executable code. The injected script runs in the affected page’s context, so it may be able to read or change content loaded from that site, access that site’s local storage, or send HTTP requests that include the user’s credentials.

The result can be exposure of sensitive information or actions performed as the signed-in user, depending on the site, its data and the browser’s protections. It is not the same as a script automatically reading every open tab, escaping browser isolation, or controlling the operating system. Mozilla’s XSS documentation describes the attack as subverting the same-origin policy by getting the target site to run malicious code within its own context.

How an XSS attack happens

  1. An attacker influences input. The input might come from a URL parameter or content submitted by a user.
  2. The site treats that input unsafely. A page might insert it into HTML without appropriate handling—for example, client-side code might pass it to an HTML-parsing sink such as innerHTML. Unsafe server-rendered output can create the same kind of problem.
  3. The browser interprets the result as code. Rather than remaining ordinary text, the attacker-influenced content executes in the target site’s page context.
  4. The code acts through that context. It may interact with the page’s content or make requests to the site that carry the user’s credentials. What it can expose or do depends on the site and the protections in place.

The essential failure is not that a site uses JavaScript. It is that untrusted input is allowed to become executable in a page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Why another open website usually cannot read your signed-in pages

Browsers use the same-origin policy to restrict how a document or script from one origin can interact with resources from another. An origin is the combination of the scheme, host and port. Changing only the path does not make a new origin. For example, a different website cannot ordinarily read a signed-in webmail page merely because both pages are open in the same browser.

XSS changes the situation because the target site itself runs the attacker’s code inside its origin. This is why XSS is a failure at the boundary of a particular site, not a general grant of access to every site in the browser. The policy does not block every cross-origin action; it limits particular kinds of access. The script’s effective authority depends on where it runs and which browser and site controls apply.

Rank #2
Yoidesu USB Fingerprint Reader for Windows Hello, Plug & Play Security Key
  • Windows Hello for Windows 10/11 - Only works with Windows Hello on Windows 10/11 PCs and laptops. Plug the USB fingerprint reader into your computer and sign in with one touch. Not compatible with Mac, macOS, Linux or Chrome OS.
  • Plug-and-Play Fingerprint Login - No extra app is needed on most genuine Windows systems. Insert the USB fingerprint scanner, set up fingerprint sign-in through Windows Hello, and unlock your PC without typing long passwords every time.
  • Fast 0.5s 360° Recognition - Capacitive fingerprint technology supports quick authentication in about 0.5 seconds. 360° touch recognition helps read your fingerprint from different angles for faster, smoother daily login.
  • Compact Scanner for PC & Laptop + Multi-User Support - Small, lightweight USB design works well for desktops, laptops, office PCs and shared home computers without built-in fingerprint sensors. Supports multiple Windows accounts and up to 10 fingerprints per user account. Smart-ID security helps protect saved passwords and encrypted folders with fingerprint access.
  • Important Notes — Please Read Before Purchase - Support for Win10/11 32/64 bit original system. Not fit for the streamlined version. The Lite version has trimmed the biometric component, the fingerprint login device will not be able to recognize the Hello fingerprint option.It merely supports Windows Hello, does not fit for encrypting USB drives/files, and can merely support Windows system.It is recommended to prioritize plugging into the USB 2.0 interface of the motherboard. USB 3.0 docking stations are prone to power supply/interference and unstable recognition.

What about scripts loaded from another website?

A JavaScript file does not run with the privileges of the server that hosts the file. If a page loads an external script, the browser executes it in the embedding page’s context. That means a compromised or malicious third-party script can affect the site that includes it, even when the script file comes from a different origin.

Website operators can restrict which scripts a page may load or execute with a Content Security Policy (CSP), and use Subresource Integrity (SRI) to help detect unexpected changes to a fetched script. These controls reduce risk but do not make unsafe application code harmless.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

How site owners can reduce the risk

Keep untrusted input from becoming executable

The primary defense is to handle data according to the context in which it will appear. Use appropriate output encoding and sanitization, and avoid inserting untrusted values into HTML when ordinary text rendering will do. Client-side code needs the same care as server-rendered pages: using a framework or writing code in the browser does not by itself prevent unsafe insertion.

Add a Content Security Policy as a second layer

A CSP tells the browser which resources and scripts a page may load or execute. A strict policy based on nonces or hashes can prevent injected scripts without an approved nonce or hash from running. Depending on how it is configured, CSP can also block inline event handlers and execution patterns such as eval(). Avoid weakening a policy with exceptions such as unsafe-inline where possible.

Rank #4
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

CSP is not a substitute for safe output handling: it limits what the browser will execute if another defense fails, while safe handling addresses the underlying cause. An overly broad allowlist or unsafe exceptions can reduce a policy’s protection. For deployment, MDN recommends starting with Content-Security-Policy-Report-Only to identify problems before enforcing a policy. Site operators need to test a policy against the scripts their site legitimately uses. See MDN’s CSP implementation guide and OWASP’s CSP Cheat Sheet.

Check third-party scripts

Because an included external script executes in the page’s context, third-party dependencies deserve careful control. SRI lets a page specify an expected cryptographic hash for a fetched resource, helping the browser detect a resource that has changed unexpectedly. It is a useful safeguard for applicable scripts, not a replacement for reviewing what a site includes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
VeriMark™ IT 2.0 USB-C® Fingerprint Key - Windows Hello & Windows Hello for Business, 360° Fingerprint Reader, Password-Free Login K64705WW
  • Windows Hello and WebAuthn ready for password free login
  • Certified to Microsoft’s highest fingerprint security standards (ESS & SDCP) for robust, hardware-isolated authentication.
  • Windows Hello Enhanced Sign-in Security requires a PC running Windows 11 with the latest updates. Supports next-gen Windows features, including Copilot PC+ Recall. Supports Windows 11 on x86 and ARM architectures.
  • Match-in-Sensor with on-device biometric processing. 360° fingerprint sensor with AI-enhanced accuracy
  • Low False Rejection Rate (FRR) of 2.2% and a False Acceptance Rate (FAR) of 0.0001%
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How this differs from other threats

XSS, phishing, malware installation, browser exploits and operating-system compromise are different events. XSS concerns attacker-controlled code running in a target site’s page context. It can have serious consequences for that site and its users, but it does not by itself establish that the attacker has escaped browser isolation or taken control of the device.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.