Peripheral Instinct: How External Devices Breach Browser Sandboxes
Leon Trampert, Lorenz Hetterich, Lukas Gerlach, Mona Schappert, Christian Rossow, Michael Schwarz
Abstract
Browser APIs such as WebHID, WebUSB, Web Serial, and Web MIDI enable web applications to interact directly with external devices. The support of such APIs in Chromium-based browsers, such as Chrome and Edge, radically changes the threat model for peripherals and increases the attack surface. In the past, devices could assume a trusted host, i.e., the operating system. Now, the host is a potentially malicious website and cannot be trusted. We show how this changed threat model leads to security and privacy problems, up to a complete compromise of the operating system. While the API specifications list initial security considerations, they shift the responsibility to (unprepared) device vendors. We systematically analyze the security implications of external devices exposed by such new APIs. By reverse-engineering peripheral devices of several popular widespread vendors, we show that many vendors allow controlling devices via Web APIs up to reprogramming or even fully replacing the firmware. Consequently, web attackers can reprogram devices with malicious payloads and custom firmware without requiring any physical interaction. To demonstrate the security implications, we build several full-chain exploits, leading to arbitrary code execution on the victim system, circumventing the browser sandbox. Our research shows that browser security should not rely on the secure implementation of third-party hardware. CCS Concepts • Security and privacy → Browser security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 90f24e75-a574-4d5c-ac27-d7878ce9684fCited by top-tier papers1
Ask how each one uses itBuilds on9
- Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in DomainsChaz Lever, Robert J. Walls, Yacin Nadji, David Dagon et al.S&P 2016 · 76 citations
- JavaScript Zero: Real JavaScript and Zero Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel GrussNDSS 2018 · 67 citations
- Making USB Great Again with USBFILTERDave (Jing) Tian, Nolen Scaife, Adam Bates, Kevin R. B. Butler et al.USENIX Security 2016 · 56 citations
- SoK: "Plug & Pray" Today - Understanding USB Insecurity in Versions 1 Through CJing (Dave) Tian, Nolen Scaife, Deepak Kumar, Michael D. Bailey et al.S&P 2018 · 52 citations
- SoK: Exploiting Network PrintersJens Müller, Vladislav Mladenov, Juraj Somorovsky, Jörg SchwenkS&P 2017 · 31 citations
Related papers
- Master of Web Puppets: Abusing Web Browsers for Persistent and Stealthy ComputationPanagiotis Papadopoulos, Panagiotis Ilia, Michalis Polychronakis, Evangelos P. Markatos et al.NDSS 2019 · 36 citations
- Browser Permission Mechanisms DemystifiedKazuki Nomoto, Takuya Watanabe, Eitaro Shioji, Mitsuaki Akiyama et al.NDSS 2023
- A Formal Security Analysis of the W3C Web Payment APIs: Attacks and VerificationQuoc Huy Do, Pedram Hosseyni, Ralf Küsters, Guido Schmitz et al.S&P 2022 · 6 citations
- EmPoWeb: Empowering Web Applications with Browser ExtensionsDolière Francis SoméS&P 2019 · 60 citations
- "The Web/Local" Boundary Is Fuzzy: A Security Study of Chrome's Process-based SandboxingYaoqi Jia, Zheng Leong Chua, Hong Hu, Shuo Chen et al.CCS 2016 · 27 citations
