Windows Defender detection triggered when searching "deepseek" in Google after installing Brave via StandaloneSilentSetup (Microsoft Store / GitHub Releases)

Hello Brave team,

I would like to report a reproducible issue related to Windows Defender detections when using Brave Browser installed via the StandaloneSilentSetup installer.

Environment:

Issue description:

When installing Brave Browser using the StandaloneSilentSetup version (as provided via Microsoft Store installation flow or downloaded directly), Windows Defender triggers a detection when performing a Google search for the keyword:

deepseek

The detection is reported as a Trojan-related alert in Windows Defender and appears to originate from Brave browser cache or temporary browsing data.

The same behavior can be reproduced by simply opening Google and searching for “deepseek”.

Observed behavior:

  • Windows Defender triggers a detection during or shortly after performing the search.
  • The detection references browser cache / temporary files generated by Brave.
  • The issue appears when using Brave Browser installed via StandaloneSilentSetup.
  • The detection does NOT appear when:
    • Using the normal Brave installer downloaded from brave.com or GitHub Releases
    • Using other browsers
    • Using Brave in Incognito mode

I would like to understand whether:

  1. This behavior is reproducible on other machines using the same StandaloneSilentSetup installer
  2. This is a false positive specific to Windows Defender signature detection
  3. Or if there is any known interaction between Brave (StandaloneSilentSetup builds) and Windows Defender that could trigger this detection

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.