acceptodds
Under review as a conference paper at ICLR 2027

Mind the Boundary: Data Leakage in Native-Store LLM Browser Extensions

Abstract

LLM browser extensions legitimately send some user content to remote models, making outbound traffic alone an inadequate privacy signal. We present a four-browser measurement study that first identifies LLM-related candidates, then uses package analysis to characterize their permissions and model-facing data surfaces, and finally executes downloadable extensions with synthetic markers to observe first-hop transmission. Among 6874 successfully analyzed candidate packages, The risks identified through static analysis, such as unnecessary browser permissions and AI-related content collection are widespread. Runtime evidence is substantially narrower: most detected transmissions carry explicit user input, while a small subset also carries context outside our predeclared profile-and-action boundary. A controlled context experiment further shows that richer and attacker-influenced pages can induce additional out-of-bound transmissions. Our results have led to the separation of static risks and risks under actual operation, and have revealed the proportion and correlation between the two in the real world.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.