Browser Permission Mechanisms Demystified
Kazuki Nomoto, Takuya Watanabe, Eitaro Shioji, Mitsuaki Akiyama, Tatsuya Mori
摘要
—Modern Web services provide rich content by accessing resources on user devices, including hardware devices such as cameras, microphones, and GPSs. Web browser vendors have adopted permission mechanisms that achieve appropriate control over access to such resources to protect user privacy. The permission mechanism gives users the ability to grant or deny their browser access to resources for each website. Despite the importance of permission mechanisms in protecting user privacy, previous studies have not been conducted to systematically understand their behavior and implementation. In this study, we developed P ERMIUM , a web browser analysis framework that automatically analyzes the behavior of permission mechanisms implemented by various browsers. Using the P ERMIUM framework, we systematically studied the behavior of permission mechanisms for 22 major browser implementations running on five different operating systems, including mobile and desktop. We determined that the implementation and behavior of permission mechanisms are fragmented and inconsistent between operating systems, even for the same browser (i.e., Windows Chrome vs. iOS Chrome) and that the implementation inconsistencies can lead to privacy risks. Based on the behavior and implementation inconsistencies of the permission mechanism revealed by our measurement study, we developed two proof-of-concept attacks and evaluated their feasibility. The first attack uses the permission information collected by exploiting the inconsistencies to secretly track the user. The second attack aims to create a situation in which the user cannot correctly determine the origin of the permission request, and the user incorrectly grants permission to a malicious site. Finally, we clarify the technical issues that must be standardized in privacy mechanisms and provide recommendations to OS/browser vendors to mitigate the threats identified in this study.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Peripheral Instinct: How External Devices Breach Browser SandboxesLeon Trampert, Lorenz Hetterich, Lukas Gerlach, Mona Schappert 等WWW 2025 · 被引用 2 次
- BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User InterfaceMingi Jung, Donggyu Kim, Mijung Kim, Seongil WiUSENIX Security 2026
它引用的顶会 Paper7
- Hindsight: Understanding the Evolution of UI Vulnerabilities in Mobile BrowsersMeng Luo, Oleksii Starov, Nima Honarmand, Nick NikiforakisCCS 2017 · 被引用 43 次
- A Large Scale Study of User Behavior, Expectations and Engagement with Android PermissionsWeicheng Cao, Chunqiu Xia, Sai Teja Peddinti, David Lie 等USENIX Security 2021 · 被引用 42 次
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 被引用 39 次
- DNS Cache-Based User TrackingAmit Klein, Benny PinkasNDSS 2019 · 被引用 34 次
- Tales of Favicons and Caches: Persistent Tracking in Modern BrowsersKonstantinos Solomos, John Kristoff, Chris Kanich, Jason PolakisNDSS 2021
相关 Paper
- Navigating Murky Waters: Automated Browser Feature Testing for Uncovering Tracking VectorsMir Masood Ali, Binoy Chitale, Mohammad Ghasemisharif, Chris Kanich 等NDSS 2023
- Detection of Inconsistencies in Privacy Practices of Browser ExtensionsDuc Bui, Brian Tang, Kang G. ShinS&P 2023
- Latex Gloves: Protecting Browser Extensions from Probing and Revelation AttacksAlexander Sjösten, Steven Van Acker, Pablo Picazo-Sanchez, Andrei SabelfeldNDSS 2019 · 被引用 36 次
- Websites Need Your Permission Too - User Sentiment and Decision-Making on Web Permission Prompts in Desktop ChromeMarian HarbachCHI 2024 · 被引用 3 次
- A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the WebStefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes 等USENIX Security 2020
