|
Description
|
The rapid proliferation of AI-enabled browser extensions has introduced significant security vulnerabilities. These client-side applications, distributed with exposed source files, frequently embed API keys from AI platforms - credentials designed to track usage for billing and prevent misuse. The exposure of these API keys poses substantial financial and operational risks to extension developers. This study presents the first comprehensive security analysis of API key leakage in browser extensions. We systematically analyzed 163,924 extensions across Chrome, Firefox, and Edge stores, uncovering 3,677 unique leaked API keys across 4,145 extensions. Most critically we identified 300 exposed AI platform keys across 309 extensions that collectively serve 1,045,339 users. Furthermore, our analysis reveals prominent reuse of API keys across different extensions, along with instances of multiple keys being used by single extensions. In this paper, we introduce the CRX-ray detection framework to identify API key leakage in browser extensions. By open-sourcing CRX-ray, we aim to empower developers to identify and mitigate API key leakage, fostering the development of more secure browser extensions that protect both developers and users. (2026-06-01)
***This entry has been automatically imported via OpenAlex by LIST harvest scripts. Please refer to https://doi.org/10.1145/3779208.3785378 for the original and latest version of the publication*** (2026-07-01)
|