Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: browser-extension (7 articles)Clear

Popular Chrome ad blocker extensions disclose selling users' browsing data to third parties

LayerX research found dozens of Chrome extensions, reaching millions of users, that legally sell or share user data under terms accepted at install. Among ad blockers, it confirmed eight reserving the right to sell or share user information, together reaching over 5.5 million users. Stands AdBlocker, with three million users, sells browsing data for market analytics, and Poper Blocker, with two million users, discloses selling identifiers, browsing activity, and behavioral profiles inferred from visited URLs. Smaller ad blockers route browsing data and even AI conversations through data brokers. The finding shows tools installed to stop tracking can themselves become data exfiltration channels, a browser extension supply chain risk static malware scanning misses.

Check
Inventory browser extensions across managed fleets, remove data-selling ad blockers like the named ones, and enforce an allowlist for permitted extensions.
Affected
Users who installed these ad blockers consented in the terms to having their browsing data, identifiers, and inferred profiles sold or shared with third parties.
Fix
Deploy an enterprise extension allowlist, review extension permissions and privacy terms, and educate users that ad blockers can monetize their data.

One malicious extension can hijack the built-in AI in several browsers

Researchers at Forever Security showed that a single malicious browser extension can hijack the AI assistant built into several AI-enabled browsers, including Chrome, Edge, Comet, Opera Neon, and Claude in Chrome. The core problem is that putting an AI agent inside the browser reopens a privilege-escalation path browsers normally work to close, letting a low-privilege extension reach a high-privilege part of the browser. Two of the findings received identifiers, one in Chrome, patched in January, and one in Edge, patched in July, while the others were fixed through bug bounties without dates. There is no evidence of real-world use yet, and each method still requires the user to install the extension.

Check
Update Chrome, Edge, and other AI-enabled browsers to their latest versions, review installed extensions and remove untrusted ones, and restrict extension installation through browser policy where possible.
Affected
Users of browsers with a built-in AI assistant who install a malicious extension; it can escalate from its low privileges to the high-privilege in-browser AI agent, controlling the assistant and its access.
Fix
Keep AI-enabled browsers updated, enforce extension allowlisting by policy, limit what the built-in AI agent can access, and treat the in-browser AI assistant as a privilege boundary extensions must not reach.

Malicious Twitch extension leaks live session tokens from about 30,000 users

Researchers at Socket found that a browser extension called "Twitch Enhanced Viewer," installed by roughly 30,000 Chrome and Firefox users, secretly forwards users' live Twitch session tokens to proxy servers run by a Russian-language bot service. Those tokens let anyone holding them act on the account without the password or two-factor authentication. The extension's advertised features, like ad blocking, forced 1080p, and region unlocking, are real and serve as cover: to deliver them it routes Twitch's video requests through operator-controlled proxies and skims the authentication token along the way. Earlier versions posted stolen tokens to a dedicated collection endpoint. Affected users should remove it and sign out of all Twitch sessions.

Check
Remove the Twitch Enhanced Viewer extension if installed, then sign out of all Twitch sessions to invalidate stolen tokens, and review installed browser extensions that hold account or broad site permissions.
Affected
Users who installed the extension on Chrome or Firefox; it forwards their live Twitch session tokens to a third party, granting account access without the password or two-factor authentication.
Fix
Restrict browser extension installation by policy, review and limit extension permissions, treat any extension that can read authenticated sessions as high-risk, and invalidate sessions if a token-stealing extension was used.

PEEP toolkit hijacks Chrome and Edge into backdoors that run host commands

Researchers disclosed a post-exploitation toolkit called PEEP that turns Chrome and Edge into backdoors for stealing credentials and running commands on the host. After an attacker already has administrative or code-execution access, PEEP's installer injects a malicious extension disguised as a bookmarks tool directly into browser profiles, forging Chromium's own integrity settings to bypass the Web Store and skip user approval prompts. The planted extension then serves as a covert channel to harvest credentials and execute operating-system commands. Because it abuses a trusted, ever-present browser and hides its extension from the usual checks, it can persist quietly on a compromised machine, a reminder that browsers themselves are a rich post-compromise attack surface.

Check
Hunt for tampering with Chromium's secure preferences file and for extensions loaded outside the Web Store, and treat an unexpected browser extension on a server or admin workstation as a possible backdoor.
Affected
Windows systems an attacker already compromised with admin or code-execution access; PEEP silently installs a browser extension by forging integrity settings, then uses it to steal credentials and run host commands.
Fix
Enforce enterprise extension allowlisting through browser policy, monitor for secure-preferences tampering and unapproved extensions, restrict local administrator rights that enable the install, and include browser artifacts in endpoint detection and incident response.

Adobe extension flaw let any website read a visitor's WhatsApp Web chats

Guardio Labs disclosed HermeticReader, a flaw chain in the Adobe Acrobat extension for Chrome that let an attacker controlled web page read data from a visitor's WhatsApp Web session. Tracked as CVE-2026-48294 and rated 7.4, it is a cross origin disclosure issue affecting versions up to 26.5.2.2, installed on roughly 329 million browsers. Any site could disguise commands as internal extension messages, activate the extension's WhatsApp integration, and redirect its privileged page operations into the WhatsApp tab, extracting chats, contacts, and message previews. No malware, stolen credentials, or WhatsApp flaw was involved. Adobe patched within days.

Check
Confirm the Adobe Acrobat Chrome extension is updated to 26.5.2.3 or later across managed browsers, and review which other extensions hold broad permissions across sensitive web applications.
Affected
Anyone running the Adobe Acrobat Chrome extension at version 26.5.2.2 or earlier with an active WhatsApp Web session (CVE-2026-48294); visiting a malicious page was enough to expose chats and contacts.
Fix
Update the extension, govern browser extensions with allow lists and permission reviews, and remember that a widely trusted extension can turn any visited page into a route to session data.

Popular ModHeader dev extension pulled after hidden history collector found

Google and Microsoft removed ModHeader, a header-editing browser extension popular with developers, with about 1.6 million installs, after researchers at Stripe OLT found a hidden browsing-history collector inside the official, signed store version. The collector was dormant, gated off by an empty allow-list, and no evidence has emerged that it ever sent data, but its presence in a trusted, signed extension is the concern. Its design frustrated automated review: the data was encrypted, the upload was switched off so sandboxes saw nothing leave, and malicious code was blended into a legitimate codebase, so scanners rated it low risk. It is a reminder that a store signature proves origin, not safe behavior.

Check
Check whether ModHeader is installed on developer or tester machines, remove or update it per the vendors' guidance, and review which browser extensions have broad permissions across your organization.
Affected
Developers and testers who installed ModHeader, and their organizations; a trusted, signed extension shipped a dormant collector capable of recording visited domains, showing signed extensions can still hide unwanted behavior.
Fix
Govern browser extensions with allow-lists and permission reviews, do not treat a store signature as proof of safe behavior, prefer minimal necessary extensions, and monitor for extensions contacting unfamiliar external endpoints.

Edgecution malicious Edge extension escapes the browser sandbox to plant a backdoor

Zscaler detailed Edgecution, a malicious Microsoft Edge extension used in ransomware-linked intrusions that abuses Chrome's native messaging feature, which normally lets extensions talk to desktop apps, to break out of the browser sandbox and run a Python backdoor on the host. The extension beacons to a command server and relays commands to the backdoor, giving attackers filesystem access and code execution, while running in a hidden headless browser to stay invisible. Attacks start with social engineering on Microsoft Teams, where the actor poses as IT support and directs employees to a fake "Outlook Updates" page. Researchers tie the activity to an access broker linked to the Payouts King ransomware operation.

Check
Review which browser extensions are installed across the organization and audit native messaging host registrations, and treat unsolicited Microsoft Teams messages from supposed IT support directing software installs as suspicious.
Affected
Organizations whose employees can install browser extensions and be reached by external Microsoft Teams messages; the technique escapes the browser sandbox to give attackers host-level access for ransomware staging.
Fix
Restrict browser extension installation through policy, control native messaging host configurations, lock down external Teams contact, and train staff to reject IT-support prompts pushing browser or software updates.