HOPE_16 (2025): "CRXaminer - Deep Dive Into Chrome Extensions (Plus Tool)" (Download)
Mark El-Khoury
Friday, August 15, 2025: 2:00 pm (Tobin 201/202): You spend your time configuring HTTP headers and hardening your containers. Meanwhile your CFO just downloaded a Chrome extension to make the font in Gmail Comic Sans. What are Chrome extensions, exactly? This talk will dive into details, including format, contents, static analysis with custom rules, threat modeling (when does this even matter?), and some of the unique challenges of building a security scanner. A tool will be demoed that has just been released for this: CRXaminer (crxaminer.tech). You will learn how you can immediately start using it.