Sentinel: Securing Legacy Firefox Extensions
- Kaan Onarlioglu, Ahmet Buyukkayhan, William Robertson, Engin Kirda
- Journal of Computers and Security 49 (0)
A poorly designed web browser extension with a security vulnerability may expose the whole system to an attacker. Therefore, attacks directed at “benign-but-buggy” extensions, as well as extensions that have been written with malicious intent, pose significant security threats to a system running such components. Recent studies have indeed shown that many Firefox extensions are over-privileged, making them attractive attack targets. Unfortunately, users currently do not have many options when it comes to protecting themselves from extensions that may potentially be malicious. Once installed and executed, the extension is considered trusted.