Skip to main content

Half of Google Chrome extensions may be collecting your personal data

Data risk management company Incogni has found that half of every installed Google Chrome extension has a high to very high risk of collecting personal data, showing a strong correlation to the number of permissions given.

After analyzing 1,237 Chrome extensions found in the Chrome Web Store, a study by Incogni has uncovered some troubling findings. Nearly half (48.7%) of the extensions were found to potentially expose users’ personally identifiable information (PII), distribute malware and adware, and record passwords and financial information.

Incogni table of Most data-hungry extensions collecting the most data by use case.
Image used with permission by copyright holder

When Incogni drilled down its findings to determine the risk impact of the permission given to extensions during installation, it found that 1 in 4 (27%) of them collect data. An interesting nugget is writing extensions, including Grammarly and Compose AI, tend to be the most data-hungry, with almost 80% of them catching at least one data point at a time.

Recommended Videos

Writing extensions also ask for the most permissions, netting the highest risk scores of 3.7 out of 5.0, so if you have these installed, do be sure to take the necessary measures to augment your browsers and exercise caution before installing new ones.

Incogni table of Most data-hungry writing Chrome extensions.
Image used with permission by copyright holder

Since most users won’t know what risks each given permission entails or the fact that extensions can’t function without certain permissions, it is advised that one should install extensions only from trusted developers. Still, even developers with high user ratings or reliable software development do not guarantee complete protection. The point is to be vigilant and practice common sense when it comes to granting and reviewing permissions.

Please enable Javascript to view this content

As Aleksandras Valentij, Information Security Officer at Surfshark says, “why would an ad blocker need audio capture access or access to your file system? If you have doubts, simply don’t use that particular add-on. There are plenty of alternatives for each add-on out there.”

Aaron Leong
Former Digital Trends Contributor
Aaron enjoys all manner of tech - from mobile (phones/smartwear), audio (headphones/earbuds), computing (gaming/Chromebooks)…
Google Chrome has its own version of Window’s troubled Recall feature
google chrome version of recall blog header

Google has announced a number of AI features for the Chrome web browser, one of which can search through your browsing history using plain language. It's a bit like a toned-down version of Microsoft's Recall feature, which did this on the level of the entire operating system.

The example given entails typing the following question into your search history: "What was that ice cream shop I looked at last week?" Chrome will then dig through and pull up sites relevant to your question. It'll then suggest a website as the "AI Best Match."

Read more
Update your Chrome browser now to gain this critical security feature
Google Chrome icon in mac dock.

Yesterday, in a blog post on Google's security blog, Willian Harris from Chrome's Security Team said that Google is improving the security of Chrome cookies on Windows PCs by adopting a similar method used in macOS to help protect users from info-stealing malware.

The security update addresses session cookies that authenticate your identity when you switch apps without logging back in. Google wants to adopt the security system used by Keychain on macOS and start using "a new protection on Windows," which updates Data Protection API (DPAPI) and brings a new security tool called "application-bound" encryption.

Read more
This new Google Chrome security warning is very important
The Google Chrome logo on a black phone which is resting on a red book

Google is changing how it warns its users about suspicious files on Chrome by adding new full-page warnings and cloud scanning regarding suspicious downloads, according to Windows Report. This is an attempt to explain more precisely why it blocks specific downloads. Google says that the AI models will divide the warning into two categories: "suspicious" or "dangerous."

The new warning system primarily benefits those using the anti-phishing Enhanced protection feature. The files users upload to the cloud for an automatic scan and those that undergo a deep scan are 50 times more likely to have the AI flag them as malware.

Read more