Experimental Security Analysis of Sensitive Data Access by Browser Extensions

Experimental Security Analysis of Sensitive Data Access by Browser Extensions
复制标题

DOI:
10.1145/3589334.3645683
复制
发表时间:
2024-05
期刊:
Proceedings of the ACM on Web Conference 2024
影响因子:
--
通讯作者:
Asmit Nayak;Rishabh Khandelwal;Earlence Fernandes;Kassem Fawaz
Asmit Nayak;Rishabh Khandelwal;Earlence Fernandes;Kassem Fawaz
中科院分区:
其他
文献类型:
--
作者:
Asmit Nayak;Rishabh Khandelwal;Earlence Fernandes;Kassem Fawaz

文献摘要

相似文献

浏览器扩展提供了各种有价值的特性和功能。如果没有适当的设计或审查,它们还会构成重大的安全风险。以前的工作已经表明,浏览器扩展可以访问和操作数据字段,包括密码、信用卡号码和社会安全号码等敏感数据。在这篇文章中,我们提出了一个浏览器扩展带来的安全风险的实证研究。具体地说,我们首先构建一个概念验证扩展,它可以窃取敏感的用户信息。我们发现该扩展通过了Chrome Webstore的审查过程。然后,我们对排名前10K的网站登录页面进行测量研究,以检查扩展是否通过JS访问密码字段。我们发现没有一个密码字段是主动保护的,并且可以使用JS访问。此外,我们发现,1K网站在其页面源中以明文存储密码,包括Google.com和Cloudflare.com等流行网站。我们还分析了160K多个Chrome Web Store扩展的恶意行为,发现28K有权访问敏感字段,190个将密码字段存储在变量中。为了分析潜在恶意扩展的行为工作流,我们提出了一个LLM驱动的框架--扩展审阅者。最后,我们讨论了解决这些风险的两种对策:一种是网站开发人员可以立即采用的插件,允许他们保护敏感的输入域;另一种是浏览器级的解决方案,当扩展访问敏感的输入域时,该解决方案会提醒用户。我们的研究突出表明,迫切需要改进安全措施,以保护在线敏感用户信息。
Browser extensions offer a variety of valuable features and functionalities. They also pose a significant security risk if not properly designed or reviewed. Prior works have shown that browser extensions can access and manipulate data fields, including sensitive data such as passwords, credit card numbers, and Social Security numbers. In this paper, we present an empirical study of the security risks posed by browser extensions. Specifically, we first build a proof-of-concept extension that can steal sensitive user information. We find that the extension passes the Chrome Webstore review process. We then perform a measurement study on the top 10K website login pages to check if the extension access to password fields via JS. We find that none of the password fields are actively protected, and can be accessed using JS. Moreover, we found that 1K websites store passwords in plaintext in their page source, including popular websites like Google.com and Cloudflare.com. We also analyzed over 160K Chrome Web Store extensions for malicious behavior, finding that 28K have permission to access sensitive fields and 190 store password fields in variables. To analyze the behavioral workflow of the potentially malicious extensions, we propose an LLM-driven framework, Extension Reviewer. Finally, we discuss two countermeasures to address these risks: a bolt-on JavaScript package for immediate adoption by website developers allowing them to protect sensitive input fields, and a browser-level solution that alerts users when an extension accesses sensitive input fields. Our research highlights the urgent need for improved security measures to protect sensitive user information online.