Hello Brave team,
I would like to report a reproducible issue related to Windows Defender detections when using Brave Browser installed via the StandaloneSilentSetup installer.
Environment:
- OS: Windows 11
- Brave version: 1.91.172 (StandaloneSilentSetup installer)
- Installation source:
- Microsoft Store installation path (which downloads Brave from):
https://brave-browser-downloads.s3.brave.com/windows/v1.91.172/BraveBrowserStandaloneSilentSetup.exe
- Microsoft Store installation path (which downloads Brave from):
- Same installer is also available via GitHub Releases:
https://github.com/brave/brave-browser/releases/download/v1.91.172/BraveBrowserStandaloneSilentSetup.exe
Issue description:
When installing Brave Browser using the StandaloneSilentSetup version (as provided via Microsoft Store installation flow or downloaded directly), Windows Defender triggers a detection when performing a Google search for the keyword:
deepseek
The detection is reported as a Trojan-related alert in Windows Defender and appears to originate from Brave browser cache or temporary browsing data.
The same behavior can be reproduced by simply opening Google and searching for “deepseek”.
Observed behavior:
- Windows Defender triggers a detection during or shortly after performing the search.
- The detection references browser cache / temporary files generated by Brave.
- The issue appears when using Brave Browser installed via
StandaloneSilentSetup. - The detection does NOT appear when:
- Using the normal Brave installer downloaded from brave.com or GitHub Releases
- Using other browsers
- Using Brave in Incognito mode
I would like to understand whether:
- This behavior is reproducible on other machines using the same StandaloneSilentSetup installer
- This is a false positive specific to Windows Defender signature detection
- Or if there is any known interaction between Brave (StandaloneSilentSetup builds) and Windows Defender that could trigger this detection
