遇见数据集

Chrome Extension Permissions Risk Database (Manifest V3, 68 entries: data access, sensitivity, risk score, MV3 status, abuse vectors, mitigations)

收藏
Zenodo2026-06-26 更新2026-06-28 收录
官方服务:

资源简介:

A comprehensive open reference database of Chromium Manifest V3 extension permissions. Each of the 68 rows maps a permission (e.g. activeTab, tabs, cookies, webRequest, webRequestBlocking, declarativeNetRequest, nativeMessaging, tabCapture, identity, history, proxy, host_permissions) to its permission type (api / active / blocking / declarative / host / storage), the API scope, the concrete data category it can collect, a plain-language data-access description, a five-tier risk class from L1_minimal to L5_critical, a normalized 0-100 risk score, the sensitive-data categories exposed, whether a host permission is also required, the permission's status under Manifest V3 (including which legacy permissions were removed or gated), a common legitimate justification, the primary abuse vector, and a recommended mitigation. Compared to a plain permission list, this database captures the data-minimization and audit angle needed to decide whether an extension's requested permissions match its stated purpose. An interactive permissions auditor built on this database is available at Zovo, which reads a published extension's manifest and flags high-risk grants before install. Columns: permission_id, permission, permission_type, api_scope, data_collected, data_access_description, risk_class, risk_score_0_100, sensitive_data_categories, host_permission_required, manifest_v3_note, common_justification, abuse_vector, mitigation. License: CC0 / public domain.

提供机构:
Zenodo
创建时间:
2026-06-26
二维码
社区交流群
二维码
科研交流群
商业服务