Data Security, Privacy

287 Chrome extensions exfiltrate browsing history for millions

Novel Chrome extension-exploiting attack covertly hijacks devices. (Adobe Stock)

A security researcher has identified 287 Chrome extensions that allegedly exfiltrate browsing history data, impacting an estimated 37.4 million installations. This data, which reveals sensitive information about users' activities and interests, can potentially be deanonymized and traced back to individuals, as reported by The Register.

The researcher, known as "Q Continuum," detailed how these extensions, often disguised as harmless tools, request access to sensitive browsing history without clear justification. The collected data is then shared with numerous companies, including Similarweb, Semrush, Alibaba Group, and ByteDance, among others. While some extensions disclose data collection in their privacy policies, users may not fully grasp the extent or implications of this data harvesting. The research employed an automated testing system using a man-in-the-middle proxy to detect history leakage by correlating network requests with visited URLs.

This widespread data exfiltration highlights significant privacy concerns and the potential for misuse of user data by data brokers and corporations. It underscores the need for enhanced user awareness regarding the permissions granted to browser extensions and the often-obscured data collection practices within privacy policies.

Source: The Register

You can skip this ad in 5 seconds