00
Days
00
Hrs
00
Min
00
Sec
Submit Your Paper

"Securing the Browser: A Hybrid Static Analysis Framework for Detecting Malicious Chrome Extensions via Local Threat Intelligence"

Authors

Vikas Mishra

Assistant Professor (IN)

Article Information

DOI: 10.51583/IJLTEMAS.2026.1501000102

Subject Category: Computer Science

Volume/Issue: 15/1 | Page No: 1259-1269

Publication Timeline

Submitted: 2026-02-18

Published: 2026-02-18

Abstract

Modern web browsers have evolved into sophisticated platforms where extensions play a crucial role in enhancing user productivity and customization. However, this extensibility significantly increases the attack surface, as malicious extensions often abuse excessive permissions to harvest cookies, manipulate the Document Object Model (DOM), and exfiltration sensitive user data. Existing browser sandboxing mechanisms provide limited visibility into such threats, while cloud-based detection approaches raise privacy concerns.


This paper proposes a hybrid static analysis framework for detecting malicious Google Chrome extensions that preserves user privacy while enabling deep security inspection. The detection logic is decoupled from the browser environment and implemented as a Python-based local analysis service, which securely communicates with a lightweight Chrome extension frontend via Restful APIs.


The framework employs a dual-layer detection strategy:



  • a weighted permission risk scoring model to assess privilege abuse potential, and

  • Signature-based correlation against a local threat intelligence repository containing known malicious patterns and indicators of compromise. Experimental results demonstrate that the proposed approach improves detection accuracy and significantly reduces false positives compared to standalone permission-based techniques, offering an effective and privacy-preserving defense for end-users.

Keywords

Browser Security, Malicious Chrome Extensions, Hybrid Static Analysis, Permission Risk Assessment

Downloads

References

1. A. Aggarwal, R. Dallaway, and J. Oberheide, “I Spy with My Little Eye: Analysis and Detection of Spying Browser Extensions,” in Proc. Network and Distributed System Security Symp. (NDSS), 2017. [Google Scholar] [Crossref]

2. E. Toreini, B. Crispo, and M. Conti, “DOMtegrity: Ensuring Web Page Integrity Against Malicious Browser Extensions,” in Proc. ACM Conf. on Computer and Communications Security (CCS), 2019. [Google Scholar] [Crossref]

3. A. Kapravelos et al., “Exposing Malicious Browser Extensions,” in Proc. Network and Distributed System Security Symp. (NDSS), 2014. [Google Scholar] [Crossref]

4. D. Thomas, A. Bates, and E. Gerber, “Analyzing Permission Usage Patterns in Browser Extensions,” IEEE Security & Privacy, vol. 16, no. 4, pp. 34–43, 2018. [Google Scholar] [Crossref]

5. G. L. Pereira, “Antivirus Applied to Google Chrome Extension Malware,” Computers & Security, vol. 134, pp. 103–118, 2025. [Google Scholar] [Crossref]

6. B. Rosenzweig et al., “It’s Not Easy: Applying Supervised Machine Learning to Detect Malicious Extensions,” arXiv preprint arXiv:2509.21590, 2025. [Google Scholar] [Crossref]

7. S. Singh et al., “A Study on Malicious Browser Extensions,” arXiv preprint arXiv:2503.04292, 2025. [Google Scholar] [Crossref]

8. M. Egele, T. Scholte, E. Kirda, and C. Kruegel, “A Survey on Automated Malware Analysis Techniques,” ACM Computing Surveys, vol. 44, no. 2, pp. 1–42, 2012. [Google Scholar] [Crossref]

9. S. Agarwal et al., “Helping or Hindering? How Browser Extensions Undermine Web Security,” in Proc. IEEE Symp. on Security and Privacy (S&P), 2022. [Google Scholar] [Crossref]

10. A. Barth, “The Web Origin Concept,” Internet Engineering Task Force (IETF), RFC 6454, 2011. [Google Scholar] [Crossref]

11. Google, “Chrome Extension Manifest V3 Documentation,” Google Developers, 2023. [Google Scholar] [Crossref]

12. Y. Liu et al., “Insecure by Design: Permission Abuse in Browser Extensions,” IEEE Access, vol. 9, pp. 112345–112359, 2021. [Google Scholar] [Crossref]

13. A. Guha, M. Fredrikson, and B. Livshits, “Static Analysis of Chrome Extensions,” in Proc. Int. World Wide Web Conf. (WWW), 2015. [Google Scholar] [Crossref]

14. N. Nikiforakis et al., “You Are What You Install: Privacy Risks of Browser Extensions,” in Proc. Network and Distributed System Security Symp. (NDSS), 2012. [Google Scholar] [Crossref]

15. A. Razaghpanah et al., “Apps, Trackers, Privacy, and Regulators,” in Proc. Network and Distributed System Security Symp. (NDSS), 2018. [Google Scholar] [Crossref]

16. M. Ikram et al., “Towards Understanding and Detecting Malicious Browser Extensions,” IEEE Transactions on Dependable and Secure Computing, vol. 18, no. 4, pp. 1560–1574, 2021. [Google Scholar] [Crossref]

17. K. Borgolte et al., “Measuring and Detecting Malware in Browser Extensions,” in Proc. ACM Internet Measurement Conf. (IMC), 2018. [Google Scholar] [Crossref]

18. M. Tschantz et al., “SoK: Security and Privacy in Browser Extensions,” in Proc. IEEE European Symp. on Security and Privacy (EuroS&P), 2017. [Google Scholar] [Crossref]

19. NIST, “Guide for Conducting Risk Assessments,” NIST Special Publication 800-30, 2012. [Google Scholar] [Crossref]

20. ISO/IEC, “Information Security Risk Management,” ISO/IEC 27005, 2018. [Google Scholar] [Crossref]

21. Malwarebytes Labs, “Millions Impacted by Malicious Browser Extensions,” Technical Report, 2024. [Google Scholar] [Crossref]

22. DomainTools Intelligence, “Dual-Function Malicious Chrome Extensions,” Threat Report, 2024. [Google Scholar] [Crossref]

23. GitLab Security Research, “Malicious Browser Extensions: Threat Intelligence Report,” GitLab, 2025. [Google Scholar] [Crossref]

24. Reuters, “Cyberhaven Chrome Extension Breach Incident,” Reuters Technology News, Dec. 2024. [Google Scholar] [Crossref]

25. Cybernews Research Team, “Hundreds of Chrome Extensions Stealing User Data,” Cybernews, 2024. [Google Scholar] [Crossref]

26. Seraphic Security, “Top Browser Extension Security Risks,” Industry Whitepaper, 2023. [Google Scholar] [Crossref]

27. Cisco Talos, “Browser-Based Malware Threat Landscape,” Threat Intelligence Report, 2023. [Google Scholar] [Crossref]

28. Kaspersky Labs, “Adware and Extension-Based Malware Analysis,” Securelist Report, 2022. [Google Scholar] [Crossref]

29. Mandiant, “Threat Intelligence for Browser-Based Attacks,” Mandiant Insights, 2023. [Google Scholar] [Crossref]

30. Wikipedia Contributors, “Potentially Unwanted Program,” Wikipedia, The Free Encyclopedia, 2024. [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles

© 2026 IJLTEMAS · RSIS International. All rights reserved. ISSN 2278-2540.