Service workers are the engine behind Progressive Web Apps (PWAs). They power offline support, background sync, and push notifications. Because they run in the background, independently of any open page, they are also a natural place for abuse to hide. After PushAdMiner showed one such abuse, we asked a broader question: what else can go wrong with service workers, and how well do browsers defend against it?
Systematizing the attack surface
This systematization of knowledge (SoK) categorizes previously published and newly discovered service worker attacks, and maps each one to the mitigations browsers have (or have not) deployed. We tested the attacks across browsers to see which mitigations actually hold in practice.
Making background behavior observable
To study how service workers behave in the wild, we built SWAT, a Chromium-based forensics engine that logs service worker lifecycle events:
- Instrumented Chromium, driven by Puppeteer, records the activity of top legitimate PWAs to learn baseline behavior and derive policies.
- An anomaly detection stage checks service workers against those policies.
- When a policy is violated, the mitigation stage can stop or unregister the offending service worker.
Key findings
- Anomalous service worker behavior correlates strongly with social engineering and unauthorized tracking.
- Our disclosure led Firefox to patch the extension-API flaw behind the ExtensionHijack attack.
- Most attacks remained unmitigated. Defending against them requires broader controls on service worker execution and permissions, not isolated fixes.