Shubham Agarwal and Rafael Mrowczynski, CISPA Helmholtz Center for Information Security; Maria Hellenthal, CISPA Helmholtz Centre for Information Security; Ben Stock, CISPA Helmholtz Center for Information Security
Browser extensions play a vital role in the Web ecosystem: they enable users to customize their experience while browsing. However, the higher privileges of extensions compared to the Web applications require in-depth security considerations to not threaten the security and privacy of their users; the security and privacy mindset of developers has not been studied yet, though. In this paper, we close this research gap.
To that end, we conducted a qualitative study with extension developers from diverse backgrounds and experience levels (N=21) to identify the root causes for vulnerable extensions existing in the ecosystem. Our findings suggest that developers often implicitly acknowledge the S&P risks associated with their extensions, but they frequently lack the necessary knowledge and resources to implement effective security and privacy-protecting mechanisms. Additionally, socio-technical barriers, such as insufficient incentives and external pressures, including platform-imposed restrictions, further hinder secure development practices. Based on our findings, we offer empirically grounded takeaways for the browser extension ecosystem to help strengthen security practices and ultimately provide better protection for users.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Shubham Agarwal and Rafael Mrowczynski and Maria Hellenthal and Ben Stock},
title = {"I have no idea how to make it safer": Studying Security and Privacy Mindsets of Browser Extension Developers},
booktitle = {34th USENIX Security Symposium (USENIX Security 25)},
year = {2025},
isbn = {978-1-939133-52-6},
address = {Seattle, WA},
pages = {2927--2946},
url = {https://www.usenix.org/conference/usenixsecurity25/presentation/agarwal-shubham},
publisher = {USENIX Association},
month = aug
}

