Helping or Hindering?: How Browser Extensions Undermine Security
Shubham Agarwal
摘要
Browser extensions enhance the functionality of native Web applications on the client side. They provide a rich end-user experience by utilizing feature-rich JavaScript APIs, otherwise inaccessible for native applications. However, prior studies suggest that extensions may degrade the client-side security to execute their operations, such as by altering the DOM, executing untrusted scripts in the applications' context, and performing other security-critical operations for the user. In this study, we instead focus on extensions that tamper with the security headers between the client-server exchange, thereby undermining the security guarantees that these headers provide to the application. To this end, we present our automated analysis framework to detect such extensions by leveraging static and dynamic analysis techniques. We statically identify extensions with the permission to modify headers and then instrument the dangerous APIs to investigate their runtime behavior with respect to modifying headers in-flight. We then use our framework to analyze the three snapshots of the Chrome extension store from Jun 2020, Feb 2021, and Jan 2022. In doing so, we detect 1,129 distinct extensions that interfere with security-related request/response headers and discuss the associated security implications. The impact of our findings is aggravated by the extensions, with millions of installations dropping critical security headers like Content-Security-Policy or X-Frame-Options. CCS CONCEPTS • Security and privacy → Web application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- FV8: A Forced Execution JavaScript Engine for Detecting Evasive TechniquesNikolaos Pantelaios, Alexandros KapravelosUSENIX Security 2024 · 被引用 6 次
- Peeking through the window: Fingerprinting Browser Extensions through Page-Visible Execution Traces and InteractionsShubham Agarwal, Aurore Fass, Ben StockCCS 2024 · 被引用 4 次
- A First Look at Security and Privacy Risks in the RapidAPI EcosystemSong Liao, Long Cheng, Xiapu Luo, Zheng Song 等CCS 2024 · 被引用 3 次
- Peripheral Instinct: How External Devices Breach Browser SandboxesLeon Trampert, Lorenz Hetterich, Lukas Gerlach, Mona Schappert 等WWW 2025 · 被引用 2 次
- When AI Takes the Wheel: Security Analysis of Framework-Constrained Program GenerationYue Liu, Zhenchang Xing, Shidong Pan, Chakkrit TantithamthavornICSE 2026
它引用的顶会 Paper9
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer 等USENIX Security 2017 · 被引用 177 次
- Mystique: Uncovering Information Leakage from Browser ExtensionsQuan Chen, Alexandros KapravelosCCS 2018 · 被引用 88 次
- EmPoWeb: Empowering Web Applications with Browser ExtensionsDolière Francis SoméS&P 2019 · 被引用 60 次
- Everyone is Different: Client-side Diversification for Defending Against Extension FingerprintingErik Trickel, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis 等USENIX Security 2019 · 被引用 43 次
- DoubleX: Statically Detecting Vulnerable Data Flows in Browser Extensions at ScaleAurore Fass, Dolière Francis Somé, Michael Backes, Ben StockCCS 2021 · 被引用 35 次
相关 Paper
- You've Changed: Detecting Malicious Browser Extensions through their Update DeltasNikolaos Pantelaios, Nick Nikiforakis, Alexandros KapravelosCCS 2020 · 被引用 34 次
- Experimental Security Analysis of Sensitive Data Access by Browser ExtensionsAsmit Nayak, Rishabh Khandelwal, Earlence Fernandes, Kassem FawazWWW 2024 · 被引用 12 次
- CoCo: Efficient Browser Extension Vulnerability Detection via Coverage-guided, Concurrent Abstract InterpretationJianjia Yu, Song Li, Junmin Zhu, Yinzhi CaoCCS 2023 · 被引用 6 次
- Fingerprinting in Style: Detecting Browser Extensions via Injected Style SheetsPierre Laperdrix, Oleksii Starov, Quan Chen, Alexandros Kapravelos 等USENIX Security 2021 · 被引用 49 次
- Detection of Inconsistencies in Privacy Practices of Browser ExtensionsDuc Bui, Brian Tang, Kang G. ShinS&P 2023
