CoCo: Efficient Browser Extension Vulnerability Detection via Coverage-guided, Concurrent Abstract Interpretation
Jianjia Yu, Song Li, Junmin Zhu, Yinzhi Cao
Abstract
Extensions complement web browsers with additional functionalities and also bring new vulnerability venues, allowing privilege escalations from adversarial web pages to use extension APIs. Prior works on extension vulnerability detection adopt classic static analysis, which is unable to handle dynamic JavaScript features such as those function calls as part of array lookups. At the same time, prior abstract interpretation focuses on lightweight server-side JavaScript, which often cannot scale to client-side extension code due to object explosions in the abstract domain. In this paper, we design, implement and evaluate a novel, coveragedriven, concurrent abstract interpretation framework, called CoCo, to efficiently detect vulnerabilities in browser extensions. On one hand, CoCo parallelizes abstract interpretation with concurrent taint propagation for each branching statement, message passing and content/background scripts to detect vulnerabilities with improved scalability. On the other hand, CoCo prioritizes analysis that increases code coverage, thus further detecting more vulnerabilities. Our evaluation shows that CoCo detects at least 43 zero-day, exploitable, manually-verified extension vulnerabilities that cannot be detected by state-of-the-art works. We responsibly disclosed all the zero-day vulnerabilities to extension developers. CCS CONCEPTS • Security and privacy → Browser security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the WildYi Liu, Zhihao Chen, Yanjun Zhang, Gelei Deng et al.USENIX Security 2026 · 46 citations
- Efficient Static Vulnerability Analysis for JavaScript with Multiversion Dependency GraphsMafalda Ferreira, Miguel Monteiro, Tiago Brito, Miguel E. Coimbra et al.PLDI 2024 · 13 citations
- Peeking through the window: Fingerprinting Browser Extensions through Page-Visible Execution Traces and InteractionsShubham Agarwal, Aurore Fass, Ben StockCCS 2024 · 4 citations
- ReactAppScan: Mining React Application Vulnerabilities via Component GraphZhiyong Guo, Mingqing Kang, V. N. Venkatakrishnan, Rigel Gjomemo et al.CCS 2024 · 3 citations
- SigScope: Detecting and Understanding Off-Chain Message Signing-related Vulnerabilities in Decentralized ApplicationsSajad Meisami, Hugo Dabadie, Song Li, Yuzhe Tang et al.WWW 2025 · 2 citations
Builds on18
- Mystique: Uncovering Information Leakage from Browser ExtensionsQuan Chen, Alexandros KapravelosCCS 2018 · 88 citations
- Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the WildMarius Steffens, Christian Rossow, Martin Johns, Ben StockNDSS 2019 · 84 citations
- HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTsAurore Fass, Michael Backes, Ben StockCCS 2019 · 78 citations
- Deemon: Detecting CSRF with Dynamic Analysis and Property GraphsGiancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes et al.CCS 2017 · 74 citations
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 65 citations
Related papers
- Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style VulnerabilityMingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo et al.S&P 2023
- Helping or Hindering?: How Browser Extensions Undermine SecurityShubham AgarwalCCS 2022 · 8 citations
- Automated Exploit Generation for Node.js PackagesFilipe Marques, Mafalda Ferreira, André Nascimento, Miguel E. Coimbra et al.PLDI 2025 · 5 citations
- DoubleX: Statically Detecting Vulnerable Data Flows in Browser Extensions at ScaleAurore Fass, Dolière Francis Somé, Michael Backes, Ben StockCCS 2021 · 35 citations
- CrossFire: An Analysis of Firefox Extension-Reuse VulnerabilitiesAhmet Salih Buyukkayhan, Kaan Onarlioglu, William K. Robertson, Engin KirdaNDSS 2016 · 22 citations
