hh.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Manifesting Security: Uncovering Malicious Browser Extensions Through Manifest V2 to V3 Conversion Patterns
Halmstad University, School of Information Technology.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This work presents a novel manifest-based fingerprinting approach for detecting malicious browser extensions in the Chrome ecosystem. Browser extensions have become a critical attack surface—prior studies estimate that roughly 10% of published extensions exhibit security noteworthy or outright malicious behavior. At the same time, Google’s migration from Manifest V2 to V3 (MV2 to MV3) introduces both new security controls and conversion challenges that impact detection strategies. First, we provide the most up-to-date measurement of MV3 adoptionin the Chrome Web Store (CWS), finding that only 65.83% ofextensions had migrated to MV3 as of January 25, 2025—leaving asubstantial legacy MV2 population only months before MV2 deprecation. We then evaluate the real-world usage of GoogleChromeLabs’ Extension Manifest Converter (EMC), showing that under 1.2% of MV3 extensions show its conversion artifacts, indicating the tool's negligible adoption despite its promise. Building on these findings, we develop a four-stage pipeline to extract, compare, and weight manifest-change tokens from known malicious MV2 to MV3 conversions. Although EMC-derived patterns alone proved too sparse for reliable detection, we adapted our methodology to mine MV3-native malicious extensions and derive a granular scoring function over manifest tokens. Applied to 88,327 MV3 extensionsin the CWS, our fingerprint scores closely match prior estimatesof security-noteworthy extension prevalence (approx. 12.8% above a0.5 threshold) and distinguish malicious samples with 85.32% scoringabove 0.5. Our work (1) delivers an empirical lens on MV3 adoption and EMC usage, (2) introduces a lightweight, manifest-only detection mechanism that requires no code analysis or dynamic instrumentation, and (3) charts a new path for maintaining extension security in the post-MV2 era.

Place, publisher, year, edition, pages
2025. , p. 51
Keywords [en]
Browser Extensions, Chrome Web Store, Web Security
National Category
Security, Privacy and Cryptography
Identifiers
URN: urn:nbn:se:hh:diva-56059OAI: oai:DiVA.org:hh-56059DiVA, id: diva2:1959782
Subject / course
Digital Forensics
Educational program
Master's Programme in Network Forensics, 60 credits
Supervisors
Examiners
Available from: 2025-05-22 Created: 2025-05-21 Last updated: 2025-10-01Bibliographically approved

Open Access in DiVA

fulltext(488 kB)469 downloads
File information
File name FULLTEXT02.pdfFile size 488 kBChecksum SHA-512
800ae832bb9d03bf794d2c86667871cc00286723af2e8af0059129cdf5abe29d01f4b7b593e740be744e36c5a23a3078bb08dd0e5523d4db33f2e2876ca90224
Type fulltextMimetype application/pdf

By organisation
School of Information Technology
Security, Privacy and Cryptography

Search outside of DiVA

GoogleGoogle Scholar
Total: 470 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 567 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf