Web Hack List

Collected research

Peeking through the window: Fingerprinting Browser Extensions through Page-Visible Execution Traces and Interactions

An attacker page overwrites 571 global JavaScript APIs and 51 property accessors before an extension's injected script runs, logging each call's name, arguments, caller source and stack trace. It also enumerates globals the script sets, polls cookies, localStorage and IndexedDB, and listens for extension postMessages. Traces seen in all nine visits uniquely identify 2,747 Chrome and 572 Firefox extensions, and normalised stack traces still work against randomised extension URLs.

Record

Researcher
Shubham Agarwal, Aurore Fass and Ben Stock
Published by
doi.org
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Shubham Agarwal, Aurore Fass and Ben Stock, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .