Navigating Murky Waters: Automated Browser Feature Testing for Uncovering Tracking Vectors
Mir Masood Ali, Binoy Chitale, Mohammad Ghasemisharif, Chris Kanich, Nick Nikiforakis, Jason Polakis
Abstract
—Modern web browsers constitute complex applica- tion platforms with a wide range of APIs and features. Critically, this includes a multitude of heterogeneous mechanisms that allow sites to store information that explicitly or implicitly alters client-side state or functionality. This behavior implicates any browser storage , cache , access control , and policy mechanism as a potential tracking vector. As demonstrated by prior work, tracking vectors can manifest through elaborate behaviors and exhibit varying characteristics that differ vastly across different browsing contexts. In this paper we develop CanITrack, an automated, mechanism-agnostic framework for testing browser features and uncovering novel tracking vectors. Our system is designed for facilitating browser vendors and researchers by streamlining the systematic testing of browser mechanisms. It accepts methods to read and write entries for a mechanism and calls these methods across different browsing contexts to determine any potential tracking vulnerabilities that the mechanism may expose. To demonstrate our system’s capabilities we test 21 browser mechanisms and uncover a slew of tracking vectors, including 13 that enable third-party tracking and two that bypass the isolation offered by private browsing modes. Importantly, we show how two separate mechanisms from Google’s highly-publicized and widely-discussed Privacy Sandbox initiative can be leveraged for tracking. Our experimental findings have resulted in 20 disclosure reports across seven major browsers, which have set remediation efforts in motion. Overall, our study highlights the complex and formidable challenge that browsers currently face when trying to balance the adoption of new features and protecting the privacy of their users, as well as the potential benefit of incorporating CanITrack into their internal testing pipeline.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7c42c2ee-26a3-424a-868d-b050e5aa3e90Cited by top-tier papers5
- Fledging Will Continue Until Privacy Improves: Empirical Analysis of Google's Privacy-Preserving Targeted AdvertisingGiuseppe Calderonio, Mir Masood Ali, Jason PolakisUSENIX Security 2024 · 8 citations
- Rise of Inspectron: Automated Black-box Auditing of Cross-platform Electron AppsMir Masood Ali, Mohammad Ghasemisharif, Chris Kanich, Jason PolakisUSENIX Security 2024 · 2 citations
- You Can Rand but You Can't Hide: A Holistic Security Analysis of Google Fuchsia's (and gVisor's) Network StackInon Kaplan, Ron Even, Amit KleinNDSS 2025
- HyTrack: Resurrectable and Persistent Tracking Across Android Apps and the WebMalte Wessels, Simon Koch, Jan Drescher, Louis Bettels et al.USENIX Security 2025
- Exploiting the Shared Storage APIAlexandra Nisenoff, Deian Stefan, Nicolas ChristinCCS 2025
Builds on12
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 273 citations
- XHOUND: Quantifying the Fingerprintability of Browser ExtensionsOleksii Starov, Nick NikiforakisS&P 2017 · 104 citations
- Same-Origin Policy: Evaluation in Modern BrowsersJörg Schwenk, Marcus Niemietz, Christian MainkaUSENIX Security 2017 · 52 citations
- Hindsight: Understanding the Evolution of UI Vulnerabilities in Mobile BrowsersMeng Luo, Oleksii Starov, Nima Honarmand, Nick NikiforakisCCS 2017 · 43 citations
Related papers
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 39 citations
- Browser Permission Mechanisms DemystifiedKazuki Nomoto, Takuya Watanabe, Eitaro Shioji, Mitsuaki Akiyama et al.NDSS 2023
- Privacy Settings and Ad Perception: The Shift from Third-Party Cookies to the Privacy SandboxAbir Benzaamia, Oana GogaCHI 2026 · 1 citation
- Tales of Favicons and Caches: Persistent Tracking in Modern BrowsersKonstantinos Solomos, John Kristoff, Chris Kanich, Jason PolakisNDSS 2021
- Web Platform Threats: Automated Detection of Web Security Issues With WPTPedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara et al.USENIX Security 2024 · 6 citations
