An Empirical Study of JavaScript Inclusion Security Issues in Chrome Extensions
Fuente:
arXiv
Saved in:
| Main Author: | Guan, Chong |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Weaver: Fuzzing JavaScript Engines at the JavaScript-WebAssembly Boundary
by: Zhang, Lingming, et al.
Published: (2026)
by: Zhang, Lingming, et al.
Published: (2026)
Characterizing Phishing Pages by JavaScript Capabilities
by: Nahapetyan, Aleksandr, et al.
Published: (2025)
by: Nahapetyan, Aleksandr, et al.
Published: (2025)
Blocking Tracking JavaScript at the Function Granularity
by: Amjad, Abdul Haddi, et al.
Published: (2024)
by: Amjad, Abdul Haddi, et al.
Published: (2024)
GHunter: Universal Prototype Pollution Gadgets in JavaScript Runtimes
by: Cornelissen, Eric, et al.
Published: (2024)
by: Cornelissen, Eric, et al.
Published: (2024)
Original Sin of npm: A Study on Vulnerability Propagation in JavaScript Dependency Networks
by: Robinson, Michael, et al.
Published: (2026)
by: Robinson, Michael, et al.
Published: (2026)
Enhancing JavaScript Malware Detection through Weighted Behavioral DFAs
by: Pereira, Pedro, et al.
Published: (2025)
by: Pereira, Pedro, et al.
Published: (2025)
Obfuscating Code Vulnerabilities against Static Analysis in JavaScript Code
by: Pagano, Francesco, et al.
Published: (2026)
by: Pagano, Francesco, et al.
Published: (2026)
PatchFuzz: Patch Fuzzing for JavaScript Engines
by: Wang, Junjie, et al.
Published: (2025)
by: Wang, Junjie, et al.
Published: (2025)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
by: Zhou, Dongchao, et al.
Published: (2025)
by: Zhou, Dongchao, et al.
Published: (2025)
JsDeObsBench: Measuring and Benchmarking LLMs for JavaScript Deobfuscation
by: Chen, Guoqiang, et al.
Published: (2025)
by: Chen, Guoqiang, et al.
Published: (2025)
Characterizing JavaScript Security Code Smells
by: Kambhampati, Vikas, et al.
Published: (2024)
by: Kambhampati, Vikas, et al.
Published: (2024)
A Study of Vulnerability Repair in JavaScript Programs with Large Language Models
by: Le, Tan Khang, et al.
Published: (2024)
by: Le, Tan Khang, et al.
Published: (2024)
FV8: A Forced Execution JavaScript Engine for Detecting Evasive Techniques
by: Pantelaios, Nikolaos, et al.
Published: (2024)
by: Pantelaios, Nikolaos, et al.
Published: (2024)
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
by: Ferenc, Rudolf, et al.
Published: (2024)
by: Ferenc, Rudolf, et al.
Published: (2024)
Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis
by: Moreno, José Miguel, et al.
Published: (2024)
by: Moreno, José Miguel, et al.
Published: (2024)
Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript Bundles
by: Ali, Mir Masood, et al.
Published: (2024)
by: Ali, Mir Masood, et al.
Published: (2024)
What is in the Chrome Web Store? Investigating Security-Noteworthy Browser Extensions
by: Hsu, Sheryl, et al.
Published: (2024)
by: Hsu, Sheryl, et al.
Published: (2024)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
Static Semantics Reconstruction for Enhancing JavaScript-WebAssembly Multilingual Malware Detection
by: Xia, Yifan, et al.
Published: (2023)
by: Xia, Yifan, et al.
Published: (2023)
From Coverage to Causes: Data-Centric Fuzzing for JavaScript Engines
by: Ganguly, Kishan Kumar, et al.
Published: (2025)
by: Ganguly, Kishan Kumar, et al.
Published: (2025)
Breaking Obfuscation: Cluster-Aware Graph with LLM-Aided Recovery for Malicious JavaScript Detection
by: Liang, Zhihong, et al.
Published: (2025)
by: Liang, Zhihong, et al.
Published: (2025)
CASCADE: LLM-Powered JavaScript Deobfuscator at Google
by: Jiang, Shan, et al.
Published: (2025)
by: Jiang, Shan, et al.
Published: (2025)
The Hidden DNA of LLM-Generated JavaScript: Structural Patterns Enable High-Accuracy Authorship Attribution
by: Tihanyi, Norbert, et al.
Published: (2025)
by: Tihanyi, Norbert, et al.
Published: (2025)
Large Language Models Cannot Reliably Detect Vulnerabilities in JavaScript: The First Systematic Benchmark and Evaluation
by: Fei, Qingyuan, et al.
Published: (2025)
by: Fei, Qingyuan, et al.
Published: (2025)
Malicious GenAI Chrome Extensions: Unpacking Data Exfiltration and Malicious Behaviours
by: Seetharam, Shresta B., et al.
Published: (2025)
by: Seetharam, Shresta B., et al.
Published: (2025)
It's not Easy: Applying Supervised Machine Learning to Detect Malicious Extensions in the Chrome Web Store
by: Rosenzweig, Ben, et al.
Published: (2025)
by: Rosenzweig, Ben, et al.
Published: (2025)
Did I Vet You Before? Assessing the Chrome Web Store Vetting Process through Browser Extension Similarity
by: Moreno, José Miguel, et al.
Published: (2024)
by: Moreno, José Miguel, et al.
Published: (2024)
NoPhish: Efficient Chrome Extension for Phishing Detection Using Machine Learning Techniques
by: Thaqi, Leand, et al.
Published: (2024)
by: Thaqi, Leand, et al.
Published: (2024)
An Empirical Study on Virtual Reality Software Security Weaknesses
by: Xu, Yifan, et al.
Published: (2025)
by: Xu, Yifan, et al.
Published: (2025)
Security Challenges of Complex Space Applications: An Empirical Study
by: Paulik, Tomas
Published: (2024)
by: Paulik, Tomas
Published: (2024)
PoEW:Encryption as Consensus and Enabling Data Compression Services?
by: Guan, Chong
Published: (2026)
by: Guan, Chong
Published: (2026)
CovRL: Fuzzing JavaScript Engines with Coverage-Guided Reinforcement Learning for LLM-based Mutation
by: Eom, Jueon, et al.
Published: (2024)
by: Eom, Jueon, et al.
Published: (2024)
An Empirical Study on the Security Vulnerabilities of GPTs
by: Wu, Tong, et al.
Published: (2025)
by: Wu, Tong, et al.
Published: (2025)
Uncovering Hidden Inclusions of Vulnerable Dependencies in Real-World Java Projects
by: Schott, Stefan, et al.
Published: (2026)
by: Schott, Stefan, et al.
Published: (2026)
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
by: Chen, Zirui, et al.
Published: (2026)
by: Chen, Zirui, et al.
Published: (2026)
LLMs in the SOC: An Empirical Study of Human-AI Collaboration in Security Operations Centres
by: Singh, Ronal, et al.
Published: (2025)
by: Singh, Ronal, et al.
Published: (2025)
Security Analysis of Top-Ranked mHealth Fitness Apps: An Empirical Study
by: Forsberg, Albin, et al.
Published: (2024)
by: Forsberg, Albin, et al.
Published: (2024)
Lightweight Yet Secure: Secure Scripting Language Generation via Lightweight LLMs
by: Zhang, Keyang, et al.
Published: (2026)
by: Zhang, Keyang, et al.
Published: (2026)
Simple But Not Secure: An Empirical Security Analysis of Two-factor Authentication Systems
by: Wang, Zhi, et al.
Published: (2024)
by: Wang, Zhi, et al.
Published: (2024)
Security and Privacy Product Inclusion
by: Kleidermacher, Dave, et al.
Published: (2024)
by: Kleidermacher, Dave, et al.
Published: (2024)
Similar Items
-
Weaver: Fuzzing JavaScript Engines at the JavaScript-WebAssembly Boundary
by: Zhang, Lingming, et al.
Published: (2026) -
Characterizing Phishing Pages by JavaScript Capabilities
by: Nahapetyan, Aleksandr, et al.
Published: (2025) -
Blocking Tracking JavaScript at the Function Granularity
by: Amjad, Abdul Haddi, et al.
Published: (2024) -
GHunter: Universal Prototype Pollution Gadgets in JavaScript Runtimes
by: Cornelissen, Eric, et al.
Published: (2024) -
Original Sin of npm: A Study on Vulnerability Propagation in JavaScript Dependency Networks
by: Robinson, Michael, et al.
Published: (2026)