As with any technological development, the widespread adoption of browser extensions came with an expanded attack surface for cybercriminals to exploit. This whitepaper covers an overview of extension permissions, challenges in extension security and SquareX’s Extension Analysis Framework, a 3-layer approach to extension analysis - Metadata Analysis, Advanced Static Code Analysis and Dynamic Analysis.