KeyChaser: Unveiling API Keys in Browser Extensions
Shijin Chen, Willy Susilo, Yudi Zhang, Fuchun Guo
Abstract
API keys are essential authentication credentials for accessing online services, yet insufficient protection can cause severe breaches, from unauthorized data exfiltration to largescale service abuse. Existing research has investigated API key leakage in platforms like GitHub, mobile applications, and cloud storage, but the browser extension ecosystem remains largely neglected. Previous work relies largely on predefined patterns. This limitation is especially problematic for browser extensions, where API keys are prevalent and often embedded in novel or transformed forms. We introduce an entropy-guided heuristic detection that performs API key inference within the program context of network requests. By constructing program dependence graphs, our method traces key propagation, reconstructs transformed keys, and heuristically correlates multiple API requests to uncover diverse key formats without relying on strict pattern definition. Applied to 21,192 real-world Chrome extensions, our system detected 359 leaked API keys from 286 extensions and 125 distinct services, including 57 previously undocumented formats (176 leaks) invisible to the regex-based tool, achieving a 31.8% coverage gain. The empirical assessment verified the exploitability of many keys, allowing data leakage, service exploitation, data manipulation, and phishing attacks. We responsibly reported these findings to the Google security team, who classified the issue as P2 priority, highlighting the critical risks of insecure API key usage in browser extensions.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get eabc32ad-4b9e-4783-8bcb-5acea4f60319Cited by top-tier papers1
Ask how each one uses itRelated papers
- You've Changed: Detecting Malicious Browser Extensions through their Update DeltasNikolaos Pantelaios, Nick Nikiforakis, Alexandros KapravelosCCS 2020 · 34 citations
- How Bad Can It Git? Characterizing Secret Leakage in Public GitHub RepositoriesMichael Meli, Matthew R. McNiece, Bradley ReavesNDSS 2019 · 130 citations
- DoubleX: Statically Detecting Vulnerable Data Flows in Browser Extensions at ScaleAurore Fass, Dolière Francis Somé, Michael Backes, Ben StockCCS 2021 · 35 citations
- Detection of Inconsistencies in Privacy Practices of Browser ExtensionsDuc Bui, Brian Tang, Kang G. ShinS&P 2023
- Helping or Hindering?: How Browser Extensions Undermine SecurityShubham AgarwalCCS 2022 · 8 citations
