Lune

S&P2026顶会

KeyChaser: Unveiling API Keys in Browser Extensions

Shijin Chen, Willy Susilo, Yudi Zhang, Fuchun Guo

2026年份
1被引次数
1顶会引用

摘要

API keys are essential authentication credentials for accessing online services, yet insufficient protection can cause severe breaches, from unauthorized data exfiltration to largescale service abuse. Existing research has investigated API key leakage in platforms like GitHub, mobile applications, and cloud storage, but the browser extension ecosystem remains largely neglected. Previous work relies largely on predefined patterns. This limitation is especially problematic for browser extensions, where API keys are prevalent and often embedded in novel or transformed forms. We introduce an entropy-guided heuristic detection that performs API key inference within the program context of network requests. By constructing program dependence graphs, our method traces key propagation, reconstructs transformed keys, and heuristically correlates multiple API requests to uncover diverse key formats without relying on strict pattern definition. Applied to 21,192 real-world Chrome extensions, our system detected 359 leaked API keys from 286 extensions and 125 distinct services, including 57 previously undocumented formats (176 leaks) invisible to the regex-based tool, achieving a 31.8% coverage gain. The empirical assessment verified the exploitability of many keys, allowing data leakage, service exploitation, data manipulation, and phishing attacks. We responsibly reported these findings to the Google security team, who classified the issue as P2 priority, highlighting the critical risks of insecure API key usage in browser extensions.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper1

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖