KeyChaser: Unveiling API Keys in Browser Extensions
Shijin Chen, Willy Susilo, Yudi Zhang, Fuchun Guo
摘要
API keys are essential authentication credentials for accessing online services, yet insufficient protection can cause severe breaches, from unauthorized data exfiltration to largescale service abuse. Existing research has investigated API key leakage in platforms like GitHub, mobile applications, and cloud storage, but the browser extension ecosystem remains largely neglected. Previous work relies largely on predefined patterns. This limitation is especially problematic for browser extensions, where API keys are prevalent and often embedded in novel or transformed forms. We introduce an entropy-guided heuristic detection that performs API key inference within the program context of network requests. By constructing program dependence graphs, our method traces key propagation, reconstructs transformed keys, and heuristically correlates multiple API requests to uncover diverse key formats without relying on strict pattern definition. Applied to 21,192 real-world Chrome extensions, our system detected 359 leaked API keys from 286 extensions and 125 distinct services, including 57 previously undocumented formats (176 leaks) invisible to the regex-based tool, achieving a 31.8% coverage gain. The empirical assessment verified the exploitability of many keys, allowing data leakage, service exploitation, data manipulation, and phishing attacks. We responsibly reported these findings to the Google security team, who classified the issue as P2 priority, highlighting the critical risks of insecure API key usage in browser extensions.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- You've Changed: Detecting Malicious Browser Extensions through their Update DeltasNikolaos Pantelaios, Nick Nikiforakis, Alexandros KapravelosCCS 2020 · 被引用 34 次
- How Bad Can It Git? Characterizing Secret Leakage in Public GitHub RepositoriesMichael Meli, Matthew R. McNiece, Bradley ReavesNDSS 2019 · 被引用 130 次
- DoubleX: Statically Detecting Vulnerable Data Flows in Browser Extensions at ScaleAurore Fass, Dolière Francis Somé, Michael Backes, Ben StockCCS 2021 · 被引用 35 次
- Detection of Inconsistencies in Privacy Practices of Browser ExtensionsDuc Bui, Brian Tang, Kang G. ShinS&P 2023
- Helping or Hindering?: How Browser Extensions Undermine SecurityShubham AgarwalCCS 2022 · 被引用 8 次
