"Securing the Browser: A Hybrid Static Analysis Framework for Detecting Malicious Chrome Extensions via Local Threat Intelligence"
Authors
Vikas Mishra
Assistant Professor (IN)
Article Information
DOI: 10.51583/IJLTEMAS.2026.1501000102
Subject Category: Computer Science
Volume/Issue: 15/1 | Page No: 1259-1269
Publication Timeline
Submitted: 2026-02-18
Published: 2026-02-18
Abstract
Modern web browsers have evolved into sophisticated platforms where extensions play a crucial role in enhancing user productivity and customization. However, this extensibility significantly increases the attack surface, as malicious extensions often abuse excessive permissions to harvest cookies, manipulate the Document Object Model (DOM), and exfiltration sensitive user data. Existing browser sandboxing mechanisms provide limited visibility into such threats, while cloud-based detection approaches raise privacy concerns.
This paper proposes a hybrid static analysis framework for detecting malicious Google Chrome extensions that preserves user privacy while enabling deep security inspection. The detection logic is decoupled from the browser environment and implemented as a Python-based local analysis service, which securely communicates with a lightweight Chrome extension frontend via Restful APIs.
The framework employs a dual-layer detection strategy:
- a weighted permission risk scoring model to assess privilege abuse potential, and
- Signature-based correlation against a local threat intelligence repository containing known malicious patterns and indicators of compromise. Experimental results demonstrate that the proposed approach improves detection accuracy and significantly reduces false positives compared to standalone permission-based techniques, offering an effective and privacy-preserving defense for end-users.
Keywords
Browser Security, Malicious Chrome Extensions, Hybrid Static Analysis, Permission Risk Assessment
Downloads
References
1. A. Aggarwal, R. Dallaway, and J. Oberheide, “I Spy with My Little Eye: Analysis and Detection of Spying Browser Extensions,” in Proc. Network and Distributed System Security Symp. (NDSS), 2017. [Google Scholar] [Crossref]
2. E. Toreini, B. Crispo, and M. Conti, “DOMtegrity: Ensuring Web Page Integrity Against Malicious Browser Extensions,” in Proc. ACM Conf. on Computer and Communications Security (CCS), 2019. [Google Scholar] [Crossref]
3. A. Kapravelos et al., “Exposing Malicious Browser Extensions,” in Proc. Network and Distributed System Security Symp. (NDSS), 2014. [Google Scholar] [Crossref]
4. D. Thomas, A. Bates, and E. Gerber, “Analyzing Permission Usage Patterns in Browser Extensions,” IEEE Security & Privacy, vol. 16, no. 4, pp. 34–43, 2018. [Google Scholar] [Crossref]
5. G. L. Pereira, “Antivirus Applied to Google Chrome Extension Malware,” Computers & Security, vol. 134, pp. 103–118, 2025. [Google Scholar] [Crossref]
6. B. Rosenzweig et al., “It’s Not Easy: Applying Supervised Machine Learning to Detect Malicious Extensions,” arXiv preprint arXiv:2509.21590, 2025. [Google Scholar] [Crossref]
7. S. Singh et al., “A Study on Malicious Browser Extensions,” arXiv preprint arXiv:2503.04292, 2025. [Google Scholar] [Crossref]
8. M. Egele, T. Scholte, E. Kirda, and C. Kruegel, “A Survey on Automated Malware Analysis Techniques,” ACM Computing Surveys, vol. 44, no. 2, pp. 1–42, 2012. [Google Scholar] [Crossref]
9. S. Agarwal et al., “Helping or Hindering? How Browser Extensions Undermine Web Security,” in Proc. IEEE Symp. on Security and Privacy (S&P), 2022. [Google Scholar] [Crossref]
10. A. Barth, “The Web Origin Concept,” Internet Engineering Task Force (IETF), RFC 6454, 2011. [Google Scholar] [Crossref]
11. Google, “Chrome Extension Manifest V3 Documentation,” Google Developers, 2023. [Google Scholar] [Crossref]
12. Y. Liu et al., “Insecure by Design: Permission Abuse in Browser Extensions,” IEEE Access, vol. 9, pp. 112345–112359, 2021. [Google Scholar] [Crossref]
13. A. Guha, M. Fredrikson, and B. Livshits, “Static Analysis of Chrome Extensions,” in Proc. Int. World Wide Web Conf. (WWW), 2015. [Google Scholar] [Crossref]
14. N. Nikiforakis et al., “You Are What You Install: Privacy Risks of Browser Extensions,” in Proc. Network and Distributed System Security Symp. (NDSS), 2012. [Google Scholar] [Crossref]
15. A. Razaghpanah et al., “Apps, Trackers, Privacy, and Regulators,” in Proc. Network and Distributed System Security Symp. (NDSS), 2018. [Google Scholar] [Crossref]
16. M. Ikram et al., “Towards Understanding and Detecting Malicious Browser Extensions,” IEEE Transactions on Dependable and Secure Computing, vol. 18, no. 4, pp. 1560–1574, 2021. [Google Scholar] [Crossref]
17. K. Borgolte et al., “Measuring and Detecting Malware in Browser Extensions,” in Proc. ACM Internet Measurement Conf. (IMC), 2018. [Google Scholar] [Crossref]
18. M. Tschantz et al., “SoK: Security and Privacy in Browser Extensions,” in Proc. IEEE European Symp. on Security and Privacy (EuroS&P), 2017. [Google Scholar] [Crossref]
19. NIST, “Guide for Conducting Risk Assessments,” NIST Special Publication 800-30, 2012. [Google Scholar] [Crossref]
20. ISO/IEC, “Information Security Risk Management,” ISO/IEC 27005, 2018. [Google Scholar] [Crossref]
21. Malwarebytes Labs, “Millions Impacted by Malicious Browser Extensions,” Technical Report, 2024. [Google Scholar] [Crossref]
22. DomainTools Intelligence, “Dual-Function Malicious Chrome Extensions,” Threat Report, 2024. [Google Scholar] [Crossref]
23. GitLab Security Research, “Malicious Browser Extensions: Threat Intelligence Report,” GitLab, 2025. [Google Scholar] [Crossref]
24. Reuters, “Cyberhaven Chrome Extension Breach Incident,” Reuters Technology News, Dec. 2024. [Google Scholar] [Crossref]
25. Cybernews Research Team, “Hundreds of Chrome Extensions Stealing User Data,” Cybernews, 2024. [Google Scholar] [Crossref]
26. Seraphic Security, “Top Browser Extension Security Risks,” Industry Whitepaper, 2023. [Google Scholar] [Crossref]
27. Cisco Talos, “Browser-Based Malware Threat Landscape,” Threat Intelligence Report, 2023. [Google Scholar] [Crossref]
28. Kaspersky Labs, “Adware and Extension-Based Malware Analysis,” Securelist Report, 2022. [Google Scholar] [Crossref]
29. Mandiant, “Threat Intelligence for Browser-Based Attacks,” Mandiant Insights, 2023. [Google Scholar] [Crossref]
30. Wikipedia Contributors, “Potentially Unwanted Program,” Wikipedia, The Free Encyclopedia, 2024. [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- Predictive Health Monitoring Systems for Electric Vehicle Powertrains Using Edge AI and CAN Bus Data
- Internship Portals: A Systematic Review of Current Platforms and Future Directions
- Towards Better Urban Mobility: A Comprehensive Assessment of Pedestrian Infrastructure in Naval, Biliran Province, Philippines
- An Affordable and Sustainable Efficient Color Sorting System Using Arduino and TCS3200 Sensor
- Financial Stress and Mobility Patterns: Implication for Transportation Policy Among Jeepney Passengers