Exploiting the Shared Storage API
Alexandra Nisenoff, Deian Stefan, Nicolas Christin
Abstract
As part of an effort to replace third-party cookies, Google introduced the Shared Storage API as one of their ''Privacy Sandbox'' proposals. The Shared Storage API seeks to replace some of the benign functionalities that third-party cookies facilitate while mitigating the potential privacy harms that they can cause, such as reidentifying users across websites. Shared Storage seeks to do this by allowing third parties to store data that is not partitioned by top-level website, but limiting read access to those data. We find that the implementation and design of the API have flaws that allow for both the reidentification of users across sites and the leakage of more data than intended by Google. With the API being deployed in Google Chrome and major advertisers and trackers having completed the processes required to gain access to the API, the Shared Storage API may not do as much as intended to improve the state of privacy on the web. We present several attacks on the API that circumvent the key goals laid out by Google as well as discuss potential extensions and mitigation strategies. While we have responsibly disclosed our attacks to Google, most attacks remain possible in Chrome.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bb1300d7-fba3-468a-95f2-1d4ffb109dc9Cited by top-tier papers1
Ask how each one uses itBuilds on16
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- Auditing for Discrimination in Algorithms Delivering Job AdsBasileal Imana, Aleksandra Korolova, John S. HeidemannWWW 2021 · 105 citations
- Site Isolation: Process Separation for Web Sites within the BrowserCharles Reis, Alexander Moshchuk, Nasko OskovUSENIX Security 2019 · 105 citations
Related papers
- The Privacy-Utility Trade-off in the Topics APIMário S. Alvim, Natasha Fernandes, Annabelle McIver, Gabriel H. NunesCCS 2024 · 3 citations
- Privacy Settings and Ad Perception: The Shift from Third-Party Cookies to the Privacy SandboxAbir Benzaamia, Oana GogaCHI 2026 · 1 citation
- Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful TrackingJordan Jueckstock, Peter Snyder, Shaown Sarker, Alexandros Kapravelos et al.WWW 2022 · 15 citations
- Least Privilege Access for Persistent Storage Mechanisms in Web BrowsersGayatri Priyadarsini Kancherla, Dishank Goel, Abhishek BichhawatWWW 2025 · 2 citations
- Fledging Will Continue Until Privacy Improves: Empirical Analysis of Google's Privacy-Preserving Targeted AdvertisingGiuseppe Calderonio, Mir Masood Ali, Jason PolakisUSENIX Security 2024 · 8 citations
