Skip to main navigation Skip to search Skip to main content

CRX-ray: large-scale detection of API key leakage in browser extensions

  • Wei Zeng
  • , Zhi Wang*
  • , Valerio Bucci*
  • , Xiaoyu Chen
  • , Xin Yang
  • , Siyu Zhang
  • , Yuejun Guo
  • , Wanpeng Li
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution

2 Downloads (Pure)

Abstract

The rapid proliferation of AI-enabled browser extensions has introduced significant security vulnerabilities. These client-side applications, distributed with exposed source files, frequently embed API keys from AI platforms - credentials designed to track usage for billing and prevent misuse. The exposure of these API keys poses substantial financial and operational risks to extension developers. This study presents the first comprehensive security analysis of API key leakage in browser extensions. We systematically analyzed 163,924 extensions across Chrome, Firefox, and Edge stores, uncovering 3,677 unique leaked API keys across 4,145 extensions. Most critically we identified 300 exposed AI platform keys across 309 extensions that collectively serve 1,045,339 users. Furthermore, our analysis reveals prominent reuse of API keys across different extensions, along with instances of multiple keys being used by single extensions. In this paper, we introduce the CRX-ray detection framework to identify API key leakage in browser extensions. By open-sourcing CRX-ray, we aim to empower developers to identify and mitigate API key leakage, fostering the development of more secure browser extensions that protect both developers and users.
Original languageEnglish
Title of host publicationASIA CCS '26: Proceedings of the ACM Asia Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery
Pages1200-1212
Number of pages13
ISBN (Electronic)9798400723568
DOIs
Publication statusPublished - 04 Jun 2026

Fingerprint

Dive into the research topics of 'CRX-ray: large-scale detection of API key leakage in browser extensions'. Together they form a unique fingerprint.

Cite this