Abstract
The rapid proliferation of AI-enabled browser extensions has introduced significant security vulnerabilities. These client-side applications, distributed with exposed source files, frequently embed API keys from AI platforms - credentials designed to track usage for billing and prevent misuse. The exposure of these API keys poses substantial financial and operational risks to extension developers. This study presents the first comprehensive security analysis of API key leakage in browser extensions. We systematically analyzed 163,924 extensions across Chrome, Firefox, and Edge stores, uncovering 3,677 unique leaked API keys across 4,145 extensions. Most critically we identified 300 exposed AI platform keys across 309 extensions that collectively serve 1,045,339 users. Furthermore, our analysis reveals prominent reuse of API keys across different extensions, along with instances of multiple keys being used by single extensions. In this paper, we introduce the CRX-ray detection framework to identify API key leakage in browser extensions. By open-sourcing CRX-ray, we aim to empower developers to identify and mitigate API key leakage, fostering the development of more secure browser extensions that protect both developers and users.
| Original language | English |
|---|---|
| Title of host publication | ASIA CCS '26: Proceedings of the ACM Asia Conference on Computer and Communications Security |
| Publisher | Association for Computing Machinery |
| Pages | 1200-1212 |
| Number of pages | 13 |
| ISBN (Electronic) | 9798400723568 |
| DOIs | |
| Publication status | Published - 04 Jun 2026 |
Fingerprint
Dive into the research topics of 'CRX-ray: large-scale detection of API key leakage in browser extensions'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver