De-Googled browsers, the false choice they sell you
Brave, Firefox, Safari, Librewolf. Most alternatives to Chrome run on Google's engine. Engines, exploited flaws and agentic AI, the essentials.
Open the list of browsers that promise to free you from Google. Brave, Vivaldi, Opera, Edge, Arc, Ungoogled-Chromium. A fine spread of alternatives, a real market of dissent.
Except they nearly all run on the same engine, Blink, Google’s own. You swap the bodywork, but you keep the engine block. The diversity you think you’re choosing is set dressing.
This isn’t a plumbing detail. The rendering engine decides what your browser can do, what its flaws are, and who holds the wheel upstream.
We’ll sort this along three axes, real de-Googling, attack surface and the flaws actually exploited, and the 2025-2026 rupture, agentic AI reshuffling the deck. Without selling you Safari as an unbreakable vault. It isn’t one.
Three engines, not thirty browsers
On paper, there are dozens of browsers. In reality, only three families of rendering engine remain, Blink, developed by Google, Gecko, maintained by Mozilla, and WebKit, Apple’s Safari engine. Everything else is a skin laid over one of those three blocks.
Brave, Edge, Opera, Vivaldi, Arc, all run on Blink and its V8 JavaScript engine. In other words, on Google. When Google makes a technical decision, it propagates to the whole ecosystem, whether the vendors like it or not.
The stinging example is Manifest V3, the API change that crippled the most effective ad blockers, decided by Google for Chrome, imposed de facto on every Chromium browser.
It’s the banana monoculture. A single variety planted everywhere, and one disease is enough to fell the entire field. A single engine, a single technical direction, no real divergence possible.
Ungoogled-Chromium, often cited as the holy grail of de-Googling, illustrates the limit perfectly. Its work is real, it strips from the source code the components and services that talk to Google’s servers. But it stays built on the Chromium engine, whose trajectory is governed by Google. The code is de-Googled, the telemetry removed, but the engine remains Google’s. You unplug the trackers, you don’t change the manufacturer.
The Firefox paradox
Against this Blink tide, a single mainstream competitor holds an independent engine, Firefox, with Gecko. That’s genuine technical diversity. Except it has an awkward financier.
In 2023, the Mozilla entities booked 495 million dollars in royalties, or 76% of their 653 million in total revenue, per their own financial statements. The bulk comes from a single contract with Google, an agreement covering the browser’s default search engine.
The exact size of Google’s share is estimated by the press at around 400 to 450 million a year, but neither Google nor Mozilla has ever confirmed it to the dollar. Take that figure for what it is, an approximation.
The result, though, is anything but approximate, the “independent” alternative is funded three-quarters over by the monopoly it claims to compete with. Firefox is the competitor drawing a salary from its rival.
And that salary nearly vanished. In August 2024, Judge Amit Mehta found Google guilty of a monopoly on search, the default-engine status locking down the market. In September 2025, the remedies ruling banned exclusive distribution contracts, but explicitly allowed Google to keep paying Apple and Mozilla. Firefox came within a hair of losing its main source of revenue. Mozilla itself publicly argued that harsher sanctions would threaten Firefox’s future, a plain admission of its dependence.
The honest hierarchy of de-Googling
If you rank browsers by real de-Googling, from the most thorough to the most cosmetic, you get a clear order, one that isn’t marketing’s. The real criterion is the engine, independent of Google, or not.
Mullvad Browser and Librewolf lead. Both on Gecko, outside Google’s engine, telemetry stripped, serious anti-fingerprinting, no commercial tie to Google. Mullvad Browser is a Tor Browser without the Tor network, designed by Mullvad and the Tor Project; Librewolf is a hardened Firefox, uBlock Origin built in, settings locked down. The most hermetic, if you accept a bit of friction.
Firefox and Safari come just behind, on equal footing in principle, two engines independent of Google, Gecko for one, WebKit for the other, with the same string attached, the default-search-engine contract paid by Google. The difference, Mozilla depends on it three-quarters over to survive, Apple pockets the check without needing it, and on a Mac, Safari cuts that string in three clicks, native rendering engine, nothing to install.
Ungoogled-Chromium drops off, code cleaned of Google services, but Blink engine upstream. De-Googled on the surface, not at the root.
Brave and Vivaldi bring up the rear of the “alternatives.” Hardened Chromium, Google tracking removed on Brave’s side, ad blocking and anti-fingerprinting thrown in, but the engine stays V8. You feed Google’s upstream with every page rendered.
Edge, Opera and Chrome are off-topic the moment sovereignty comes up, Blink plus in-house telemetry, and even non-European ownership for Opera.
Putting CVEs on trial
Here’s where the classic trap begins. You line up the flaw counts, name a culprit, close the case. Wrong method.
Counting CVEs to judge an engine isn’t necessarily the most useful thing. The more market share an engine has, the more it draws offensive research, the more published flaws it generates. Chrome dominates, so Chrome concentrates the discoveries. That says little about relative security in itself.
That said, one fact holds, the volume of actively exploited flaws concentrates on V8, Chromium’s JavaScript engine. In 2024 alone, at least nine Chrome zero-days were exploited in the wild, several in V8. The CVE-2025-6554 and CVE-2025-10585 fixes, both in CISA’s KEV catalog, are recent examples of type confusion leading to code execution. To frame the scale, Google tracked 75 exploited zero-days across all products in 2024 alone.
The KEV is the catalog of actively exploited flaws maintained by the US cybersecurity agency. A flaw listed there isn’t theoretical, it’s being exploited for real.
Gecko isn’t spared, but it plays at another scale. CVE-2024-9680, a use-after-free in Firefox, was exploited then chained with a Windows sandbox escape to install persistent malware.
Conversely, CVE-2025-2857 is a good reminder to stay rigorous, patched urgently by Mozilla because it was analogous to a Chrome zero-day, it was never exploited against Firefox. Patched doesn’t mean exploited. Confusing the two skews the whole debate.
WebKit is no sanctuary
This is the moment most pro-Apple articles look away. Not us.
WebKit has its own zero-days exploited in the wild, and not just a few. In March 2025, CVE-2025-24201, described by Apple as targeting an “extremely sophisticated attack” and targeted in nature. In December, CVE-2025-43529, a use-after-free leading to remote code execution, also exploited and added to the KEV.
The WebKit profile is consistent, targeted attacks, often chained on iOS to deliver spyware to specific targets. Remote code execution triggered by a mere web page, followed by a sandbox escape, and the device is compromised.
The honest read fits in one sentence, the volume is on V8, but WebKit isn’t exempt, and the attacks aimed at it are often more sophisticated, sometimes state-sponsored. “Safari, safer,” with no nuance, is false.
Patch cadence, the real differentiator
Where the engines truly diverge is the update model.
Chrome and the Chromiums update on their own, often to an out-of-band stable build within 24 to 72 hours of detection. Fast, responsive. But the V8 surface is vast and intensely targeted.
Firefox follows its own Mozilla cycle, with an extended support release (ESR) branch for stable deployments. Demonstrated responsiveness on critical fixes, automatic browser updates.
Safari and WebKit are tied to macOS and iOS updates, with a mechanism for security fixes delivered out of the system cycle, long called Rapid Security Response and renamed “Background Security Improvements” since macOS Tahoe.
The advantage is real, the fix is baked into the OS, signed by Apple, and the attack surface is narrower, without the sprawling third-party extension ecosystem that regularly infects the Chromium world. The drawback, just as real, a WebKit fix can depend on a heavier system update, and older iOS versions stay exposed, precisely the ones the 2025 zero-days targeted.

So the balanced verdict, Safari’s advantage lies in the built-in patch cadence, the system sandbox and a reduced surface. Not in invulnerability. A nuance that changes everything.

Further reading: Privacy on macOS, the settings to change right now
Agentic AI, the flaw nobody knows how to close
Here’s the hottest axis, and the real rupture of 2025-2026. While we argue over engines, a new category of browser has opened a door nobody knows how to shut.
Browsers with an embedded agent, Perplexity’s Comet, OpenAI’s Atlas, Fellou, Opera Neon, Edge with Copilot, don’t just summarize a page. They act. Click, fill, navigate, send, on your behalf. And that’s exactly where the browser’s security model collapses.
Picture an overeager intern to whom you’ve handed your keys, your cards and your passwords. He dutifully carries out every order written on a sticky note, including the ones a stranger stuck on the documents he’s reading. The AI agent is that intern. It has your rights, your open sessions, your cookies, and it obeys the text it reads, even when that text is hostile.
This isn’t a forced lock. It’s an order whispered in the butler’s ear. The sandbox and the same-origin policy, the browser’s old defenses, are useless here. The attack breaks no memory, it hijacks meaning. It’s called indirect prompt injection.
The founding case is Comet, documented by Brave’s security team in the summer of 2025. On a simple “summarize this page,” Comet passed the page content to the model without separating the user’s instructions from the untrusted text. The demonstration did the rest, navigation to the victim’s account pages, extraction of their email, retrieval of a one-time code from their Gmail inbox, exfiltration to a Reddit comment controlled by the attacker. The one-time code included, the passphrase meant to protect you.
Brave then showed worse, near-invisible instructions hidden in an image, extracted by the text recognition of the screenshot feature, then executed as if you had typed them. Comet, Fellou, Opera Neon, same flaw. Brave’s conclusion is damning, this isn’t an isolated bug, it’s a category problem, the failure to keep a clear boundary between the user’s trusted input and untrusted web content.
Atlas, launched by OpenAI in October 2025, got tricked right out of the gate, text hidden in an online document is enough to hijack its behavior, and fake URLs trigger concealed commands. Then, in December 2025, OpenAI made the admission that matters, AI browsers might stay “always” vulnerable to prompt injection. Not a defect to fix in the next version. A problem that may be structural.
Nobody knows how to close this door. Not even those who opened it.
A distinction is in order, out of honesty. An assistant that merely summarizes, like Brave Leo, isn’t an agent that clicks and executes. Leo reads and answers, it has no hands on the wheel. The serious risk, the real one, is the agentic kind, the agent that acts on the world from a text it can’t filter. Don’t lump the two together.
And Safari in all this? Apple hasn’t shipped an agent that executes actions dictated by a page’s content. The “agentic prompt injection” surface is therefore absent from native Safari, by construction.
Let’s be precise about what that means, it’s an advantage of scope, Apple didn’t install this risky feature, it’s not some magical superiority against AI.
If you install an AI extension, or use a third-party agentic app, the attack surface returns in full. Restraint protects only as long as it lasts.
And me? When I need an AI to act on the web, I don’t hand the keys to a third-party agentic browser. I run my own assistant, in my own homemade interface, my rules, my guardrails. It’s not within everyone’s reach, I know. But it’s the only way to keep control, because on the other side there are two very distinct wounds.
There are the flaws the vendor doesn’t know how to close, the agentic prompt injection we just covered. And there are the ones it opens knowingly, by design, that is, to siphon your data wholesale.
The day an AI assistant demands full disk access just to read your Messages and reply to them, nobody made a mistake, it’s just that a company, sprawling and well-meaning (hehehe), decided your privacy and your data were the price to pay for the feature. If that reminds you of Google’s golden age… well, that’s normal!
Further reading: ChatGPT reads your Messages, the price is your whole disk
So, which browser?
No absolute ranking, it depends on what you’re after. Three profiles, three answers.
And no, I’m not going to walk you through the fine-tuning of each Chromium, a checkbox here for Brave, another there for Edge or Firefox. Ever since agentic AI opened a flaw that even its vendors call perhaps unclosable, polishing three options in a browser that runs on Google’s engine is polishing the brass while the hull takes on water. The sorting happens one level down.
You want maximum de-Googling and privacy above all. Mullvad Browser or Librewolf. Gecko engine, outside Google’s orbit, telemetry stripped, serious anti-fingerprinting. The trade-off is real, a few sites behave oddly with anti-fingerprinting, and you have to accept tinkering with a couple of settings. But on engine sovereignty, it’s the top of the basket.
Plain Firefox is still the mainstream option on the same Gecko engine, more accessible but less hardened out of the box, and with the Google-search string to cut. Librewolf is simply its factory-locked version.
The side-by-side test shows it, Safari, which you probably already have at hand, randomizes its fingerprint, while Mullvad Browser blends you into the crowd of its users. Two opposite strategies, two solid protections.

A word of warning, because Mullvad’s is more fragile than it looks. Mullvad Browser doesn’t make you anonymous by magic, it makes you look like every other Mullvad Browser user. It all rests on letterboxing, the browser lies about your window size by rounding it to standard steps, so everyone reports the same one. As long as you leave it alone.

Maximize the window, or give it an unusual size, and you can fall into a step almost nobody shares. The same test that showed you a common fingerprint then returns a nearly-unique one, as illustrated above, and there you are, trackable again. The protection holds only through your discipline, keep the default window, don’t tinker with it.
You’re on a Mac and you want the best privacy-per-effort. Safari, eyes open, and it’s my pick. You gain the patch cadence built into the OS, the system sandbox, a minimal attack surface, including against the agentic kind that Apple simply hasn’t shipped.
And its anti-fingerprinting has a quiet merit, it doesn’t collapse when you resize your window, unlike Mullvad’s letterboxing.
You don’t gain invulnerability, WebKit has its own zero-days, and you change the default search engine on install to cut the Google thread.
It’s not the most hermetic, and that’s its real limit. Safari’s telemetry, you reduce it but you never cut it off entirely, Apple keeps the upper hand. Mullvad and Librewolf ship with telemetry stripped at the source, which is what makes them preferable for anything truly sensitive, at the cost of discipline to maintain. Safari protects even when you do nothing.
You’re stuck on a Chromium browser for an extension or a site that requires it. Hardened Brave is the least bad of the family, it strips Google tracking and blocks ads. But own what you’re doing, you’re feeding Google’s engine upstream. Don’t present it as emancipation.
One rule holds for everyone, right now. Keep agentic browsers away from anything that matters, banking, health, email, work accounts. The convenience isn’t worth the exposure.
In short
The browser market sells diversity and delivers a monoculture. Most of the “alternatives to Chrome” are Chromium, hence Google upstream, and the only real mainstream competitor, Firefox, is funded three-quarters over by Google. The real dividing line isn’t the browser’s brand, it’s the engine running underneath.
On security, forget the contest for the biggest CVE count. The volume of exploited flaws is on V8, but WebKit takes its own targeted zero-days, and Firefox takes its own too.
What sets Safari apart is the built-in patch cadence and the reduced surface, not armor. And the year’s real turning point isn’t there, it’s agentic AI, a design flaw that even OpenAI calls perhaps unsolvable.
Concretely:
- Maximum de-Googling, privacy first → Mullvad Browser or Librewolf (or Firefox, to harden).
- Apple ecosystem, peace of mind, integrated patching → Safari, default search engine changed on install.
- Stuck on Chromium → hardened Brave, owning that the engine stays Google’s.
- For everyone, now → no agentic browser on your sensitive accounts, as long as the flaw stays open.
The false choice was believing that installing another browser was enough to leave Google. The real choice happens one level down, on the engine, on the patch cadence, and on the feature you refuse to enable.
Sources
The engine and the money
- Mozilla Foundation 2023 financial statements (official PDF), the primary source for the $495M in royalties and the 76% of revenue.
- OMG! Ubuntu and It’s FOSS, two reference sites on the free-software ecosystem, for the September 2025 antitrust ruling that lets Google keep paying Mozilla.
The flaws actually exploited
- CISA Known Exploited Vulnerabilities catalog, the US cybersecurity agency, primary source for actively exploited flaws.
- BleepingComputer, specialized outlet, on the Chrome zero-days and the “extremely sophisticated” WebKit zero-day.
- The Hacker News, for the two WebKit flaws patched in December 2025.
Agentic AI
- Brave security team, prompt injection in Comet and unseeable screenshot injections, the founding investigations into the agentic-browser flaw.
- TechCrunch, for OpenAI’s December 2025 admission of a possibly permanent vulnerability.
- The Register, on the widespread exposure of AI browsers to prompt injection.