• 07 3184 7575
  • August 24, 2026
  • 0 Comments

We recently came across an article published by SecurityWeek discussing new research into malicious Chrome extensions. It immediately caught our attention — not because browser extensions are new, but because of the scale involved.

More than 300 Chrome extensions were found leaking browser data, spying on users, or outright stealing sensitive information.

Given how widely browser extensions are used in modern workplaces — especially productivity and AI-based tools — we thought this was an important topic to share with our audience, along with our perspective on what it means for businesses today.

300+ Extensions Transmitting Browsing Data

Security researcher Q Continuum analysed network traffic generated by Chrome extensions and identified 287 extensions transmitting user browsing history or search engine results pages (SERP) data.

The scale is significant:

  • Over 37.4 million total users affected
  • Around 27.2 million users installed 153 extensions confirmed to leak browsing history immediately after installation

According to the research, some extensions exposed data to unsecured networks, while others transmitted it directly to collection servers. In some cases, this may have been part of monetisation models. In others, it may have been malicious by design.

Q Continuum also flagged more than 200 additional extensions as suspicious due to shared developer details with the confirmed data-leaking applications. During testing, four separate scraping entities were observed connecting to a research honeypot, suggesting potential coordination.

Based on these patterns, the researcher believes a data broker may be involved in monetising harvested data, rather than individual developers acting independently.

The extensions were linked to 32 entities, including known distributors of spyware extensions.

AI-Themed Extensions Used as a Front

In a separate report, LayerX identified 30 Chrome extensions — downloaded more than 260,000 times — that demonstrated clearly malicious behaviour.

These extensions were marketed as AI assistance tools. However, analysis revealed they shared identical internal structures, JavaScript logic, permissions, and backend infrastructure — strongly suggesting a coordinated campaign.

Among the behaviours observed:

  • Injecting full-screen iframes that load remote attacker-controlled content
  • Manipulating what users see in the browser interface
  • Extracting data from active browser tabs
  • Supporting voice recognition triggers
  • Embedding tracking pixels
  • Transmitting data to third-party infrastructure

Fifteen of the identified extensions specifically targeted Gmail users, extracting email content and sending it externally.

This type of behaviour is particularly concerning in business environments where browser sessions often provide access to corporate systems, email platforms, and cloud applications.

Why Browser Extensions Are a Serious Business Risk

Browser extensions operate inside the most trusted layer of modern work: the web browser.

Once installed, they may request permissions to:

  • Read and modify website content
  • Access browsing history
  • Interact with active sessions
  • Capture form inputs

In many cases, employees install productivity tools or AI-based extensions independently, without formal IT review.

Unlike traditional malware, malicious extensions may not trigger antivirus alerts. They can operate quietly, blending into everyday browsing activity.

In environments using platforms like Google Workspace, Microsoft 365, CRM systems, and cloud consoles, a compromised browser session can expose:

  • Email content
  • Authentication tokens
  • Customer records
  • Financial data
  • Internal dashboards

This shifts browser extensions from a minor IT concern to a meaningful security risk.

A CSB Perspective

At CSB, we see browser-based threats becoming more sophisticated and harder to detect.

The risk is no longer just malicious file downloads. It is trusted tools operating inside trusted environments.

Organisations should consider:

  • Restricting extension installations via policy
  • Whitelisting approved extensions
  • Monitoring browser-related outbound traffic
  • Reviewing extension permissions regularly
  • Including browser extensions in risk assessments
  • Educating employees about risks associated with “free” AI tools

Browser extensions may look harmless — but they can access sensitive business data at scale.

Cybersecurity today requires visibility not only at the network edge, but also within user environments.

Previous Post
Part 2: Securing ICS for the Future — From Resilience to Continuous Validation