Latex Gloves: Protecting Browser Extensions from Probing and Revelation Attacks
Alexander Sjösten, Steven Van Acker, Pablo Picazo-Sanchez, Andrei Sabelfeld
Abstract
Browser extensions enable rich experience for the users of today's web. Being deployed with elevated privileges, extensions are given the power to overrule web pages. As a result, web pages often seek to detect the installed extensions, sometimes for benign adoption of their behavior but sometimes as part of privacy-violating user fingerprinting. Researchers have studied a class of attacks that allow detecting extensions by probing for Web Accessible Resources (WARs) via URLs that include public extension IDs. Realizing privacy risks associated with WARs, Firefox has recently moved to randomize a browser extension's ID, prompting the Chrome team to plan for following the same path. However, rather than mitigating the issue, the randomized IDs can in fact exacerbate the extension detection problem, enabling attackers to use a randomized ID as a reliable fingerprint of a user. We study a class of extension revelation attacks, where extensions reveal themselves by injecting their code on web pages. We demonstrate how a combination of revelation and probing can uniquely identify 90% out of all extensions injecting content, in spite of a randomization scheme. We perform a series of large-scale studies to estimate possible implications of both classes of attacks. As a countermeasure, we propose a browser-based mechanism that enables control over which extensions are loaded on which web pages and present a proof of concept implementation which blocks both classes of attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2e5c0802-92a5-432e-9c2d-0123099c5fc3Cited by top-tier papers9
- Fingerprinting in Style: Detecting Browser Extensions via Injected Style SheetsPierre Laperdrix, Oleksii Starov, Quan Chen, Alexandros Kapravelos et al.USENIX Security 2021 · 49 citations
- Escaping the Confines of Time: Continuous Browser Extension Fingerprinting Through Ephemeral ModificationsKonstantinos Solomos, Panagiotis Ilia, Nick Nikiforakis, Jason PolakisCCS 2022 · 10 citations
- Peeking through the window: Fingerprinting Browser Extensions through Page-Visible Execution Traces and InteractionsShubham Agarwal, Aurore Fass, Ben StockCCS 2024 · 4 citations
- Only Pay for What You Leak: Leveraging Sandboxes for a Minimally Invasive Browser Fingerprinting DefenseRyan Torok, Amit LevyS&P 2023
- Unleash the Simulacrum: Shifting Browser Realities for Robust Extension-Fingerprinting PreventionSoroush Karami, Faezeh Kalantari, Mehrnoosh Zaeifi, Xavier J. Maso et al.USENIX Security 2022
Builds on5
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- XHOUND: Quantifying the Fingerprintability of Browser ExtensionsOleksii Starov, Nick NikiforakisS&P 2017 · 104 citations
- Mystique: Uncovering Information Leakage from Browser ExtensionsQuan Chen, Alexandros KapravelosCCS 2018 · 88 citations
- Extension Breakdown: Security Analysis of Browsers Extension Resources Control PoliciesIskander Sánchez-Rola, Igor Santos, Davide BalzarottiUSENIX Security 2017 · 67 citations
- CrossFire: An Analysis of Firefox Extension-Reuse VulnerabilitiesAhmet Salih Buyukkayhan, Kaan Onarlioglu, William K. Robertson, Engin KirdaNDSS 2016 · 22 citations
Related papers
- Breaking the Shield: Analyzing and Attacking Canvas Fingerprinting Defenses in the WildHoang Dai Nguyen, Phani VadrevuWWW 2025 · 2 citations
- Carnus: Exploring the Privacy Threats of Browser Extension FingerprintingSoroush Karami, Panagiotis Ilia, Konstantinos Solomos, Jason PolakisNDSS 2020
- Everyone is Different: Client-side Diversification for Defending Against Extension FingerprintingErik Trickel, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis et al.USENIX Security 2019 · 43 citations
- The Dangers of Human Touch: Fingerprinting Browser Extensions through User ActionsKonstantinos Solomos, Panagiotis Ilia, Soroush Karami, Nick Nikiforakis et al.USENIX Security 2022
- Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy LeakageSoroush Karami, Panagiotis Ilia, Jason PolakisNDSS 2021
