SAINTCON 26 · Session

The Browser's Blind Spot: How to Analyze Chrome Extensions for Hidden Risk

Speakers

Chrome extensions are installed by millions of users, including enterprise employees, yet they can be one of the least-scrutinized attack surfaces in modern security programs. They operate inside the browser after authentication, bypassing client-side controls, like EDR, entirely.

We'll walk through the full technical picture: how extensions are packaged and distributed as CRX files, what the manifest reveals, how to extract and analyze JavaScript for permission abuse and data exfiltration patterns (including the fetch() loophole that MV3 doesn't close), how to detect obfuscated code and suspicious binary asset abuse, and how LLM-based analysis pipelines can evaluate these signals at scale. The Chrome Web Store explicitly prohibits obfuscation and base64-encoded payloads, yet both appear regularly in extensions that made it through review. And when malicious extensions are discovered, the store's enforcement is often not immediate; extensions have remained available for days after being flagged.

← Full schedule

Security Briefing

Join the mission log

Occasional emails with training announcements, CFP windows, and what's launching at SAINTCON. No spam, no selling your address. Ever.

By subscribing you agree to the Privacy Policy.