Academic Journal

The Blind Spot of Extension Security: WebAssembly–JavaScript Collaborative Attacks on Chrome.

Λεπτομέρειες βιβλιογραφικής εγγραφής
Τίτλος: The Blind Spot of Extension Security: WebAssembly–JavaScript Collaborative Attacks on Chrome.
Συγγραφείς: Moon, Yeongmin, Hong, Minhyuk, Park, Jeman
Πηγή: Electronics (2079-9292); Jul2026, Vol. 15 Issue 14, p3049, 21p
Θεματικοί όροι: Malware, Computer security vulnerabilities, Source code, Internet security, Web browsers, JavaScript programming language
Περίληψη: Chrome extensions are increasingly exploited as an attack surface, yet existing static malware detectors share a critical blind spot: they analyze JavaScript but cannot inspect WebAssembly (Wasm) or reason across the Wasm–JS boundary. We exploit this gap by embedding malicious logic in Wasm modules while confining JavaScript to minimal glue code, rendering the core of each attack invisible to static analysis. Grounded in this collaborative architecture, we implement eight proof-of-concept attack scenarios across six categories—adware, malicious file delivery, forced redirection, keylogging, credential theft, and ransomware—as functioning Manifest V3 extensions. Evaluated against four representative static detectors, none achieves genuine detection: three register the samples as benign or raise no alert, and the fourth flags every sample only through systematic false positives on generated glue code. An analysis of 165,314 live extensions further shows that every permission our attacks require is already in widespread legitimate use, so such extensions would not be distinguishable from benign ones by permission-based screening alone. [ABSTRACT FROM AUTHOR]
Copyright of Electronics (2079-9292) is the property of MDPI and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Βάση Δεδομένων: Complementary Index
FullText Text:
  Availability: 0
CustomLinks:
  – Url: https://resolver.ebsco.com/c/fiv2js/result?sid=EBSCO:edb&genre=article&issn=20799292&ISBN=&volume=15&issue=14&date=20260715&spage=3049&pages=3049-3069&title=Electronics (2079-9292)&atitle=The%20Blind%20Spot%20of%20Extension%20Security%3A%20WebAssembly%E2%80%93JavaScript%20Collaborative%20Attacks%20on%20Chrome.&aulast=Moon%2C%20Yeongmin&id=DOI:10.3390/electronics15143049
    Name: Full Text Finder (for New FTF UI) (ns324271)
    Category: fullText
    Text: Full Text Finder
    MouseOverText: Full Text Finder
Header DbId: edb
DbLabel: Complementary Index
An: 195811926
RelevancyScore: 1082
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 1082.42224121094
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: The Blind Spot of Extension Security: WebAssembly–JavaScript Collaborative Attacks on Chrome.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Moon%2C+Yeongmin%22">Moon, Yeongmin</searchLink><br /><searchLink fieldCode="AR" term="%22Hong%2C+Minhyuk%22">Hong, Minhyuk</searchLink><br /><searchLink fieldCode="AR" term="%22Park%2C+Jeman%22">Park, Jeman</searchLink>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: Electronics (2079-9292); Jul2026, Vol. 15 Issue 14, p3049, 21p
– Name: Subject
  Label: Subject Terms
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Malware%22">Malware</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+vulnerabilities%22">Computer security vulnerabilities</searchLink><br /><searchLink fieldCode="DE" term="%22Source+code%22">Source code</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+security%22">Internet security</searchLink><br /><searchLink fieldCode="DE" term="%22Web+browsers%22">Web browsers</searchLink><br /><searchLink fieldCode="DE" term="%22JavaScript+programming+language%22">JavaScript programming language</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Chrome extensions are increasingly exploited as an attack surface, yet existing static malware detectors share a critical blind spot: they analyze JavaScript but cannot inspect WebAssembly (Wasm) or reason across the Wasm–JS boundary. We exploit this gap by embedding malicious logic in Wasm modules while confining JavaScript to minimal glue code, rendering the core of each attack invisible to static analysis. Grounded in this collaborative architecture, we implement eight proof-of-concept attack scenarios across six categories—adware, malicious file delivery, forced redirection, keylogging, credential theft, and ransomware—as functioning Manifest V3 extensions. Evaluated against four representative static detectors, none achieves genuine detection: three register the samples as benign or raise no alert, and the fourth flags every sample only through systematic false positives on generated glue code. An analysis of 165,314 live extensions further shows that every permission our attacks require is already in widespread legitimate use, so such extensions would not be distinguishable from benign ones by permission-based screening alone. [ABSTRACT FROM AUTHOR]
– Name: Abstract
  Label:
  Group: Ab
  Data: <i>Copyright of Electronics (2079-9292) is the property of MDPI and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edb&AN=195811926
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.3390/electronics15143049
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 21
        StartPage: 3049
    Subjects:
      – SubjectFull: Malware
        Type: general
      – SubjectFull: Computer security vulnerabilities
        Type: general
      – SubjectFull: Source code
        Type: general
      – SubjectFull: Internet security
        Type: general
      – SubjectFull: Web browsers
        Type: general
      – SubjectFull: JavaScript programming language
        Type: general
    Titles:
      – TitleFull: The Blind Spot of Extension Security: WebAssembly–JavaScript Collaborative Attacks on Chrome.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Moon, Yeongmin
      – PersonEntity:
          Name:
            NameFull: Hong, Minhyuk
      – PersonEntity:
          Name:
            NameFull: Park, Jeman
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 15
              M: 07
              Text: Jul2026
              Type: published
              Y: 2026
          Identifiers:
            – Type: issn-print
              Value: 20799292
          Numbering:
            – Type: volume
              Value: 15
            – Type: issue
              Value: 14
          Titles:
            – TitleFull: Electronics (2079-9292)
              Type: main
ResultId 1