37 Million Users Had Their Data Stolen by ‘Trusted’ Chrome Extensions — Is Your Business Browser Safe?
Browser extensions occupy a genuinely unusual position in an organization’s security posture — employees install them individually, often with a single click, and most businesses have no centralized visibility into which extensions are quietly running across their workforce’s browsers at any given time. Security researchers uncovered a campaign involving 287 Chrome extensions with a combined 37.4 million installs actively exfiltrating users’ browsing history, a separate investigation found 108 extensions harvesting session tokens and cookies from more than 20,000 enterprise users, and a third wave of extensions specifically impersonating popular AI assistants like ChatGPT and Claude stole conversation histories from over 900,000 users — several of the malicious extensions in these campaigns carried Google’s own “Featured” badge at the time they were actively stealing data. This isn’t a fringe problem confined to obscure, low-download tools; it’s happening inside extensions that looked completely legitimate.
At Webtoz, browser-level risk is exactly the kind of overlooked exposure our technology consultancy engagements are built to surface, closely tied to the access-control discipline covered in why your online presence defines your business success.
This guide covers what actually happened in these extension campaigns, why the Chrome Web Store’s own vetting process consistently misses this threat, how a browser extension gains such broad access to sensitive business data in the first place, what real business exposure this creates, and a practical process for auditing and governing extension use across your organization.
📖 In This Guide
- What Actually Happened in These Campaigns
- Why the Chrome Web Store’s Vetting Keeps Missing This
- How an Extension Gains This Much Access
- The Real Business Exposure This Creates
- The AI Impersonation Angle
- Warning Signs an Extension May Be Malicious
- Common Mistakes
- How to Govern Extension Use Across Your Business
- Final Thoughts: The Browser Is Part of Your Attack Surface
1. What Actually Happened in These Campaigns
Multiple independent security research teams uncovered these campaigns separately, and the consistency across their findings is what makes the pattern genuinely alarming rather than a single isolated incident. The largest single campaign involved 287 extensions collectively installed 37.4 million times, quietly logging and exfiltrating full browsing history to a remote server well beyond anything the extensions’ stated functionality — a screenshot tool, a coupon finder, a productivity utility — ever needed, while a separate, more enterprise-focused campaign specifically targeted session tokens and authentication cookies across more than 20,000 corporate users, effectively giving attackers a path to hijack active logged-in sessions without ever needing a victim’s actual password.
2. Why the Chrome Web Store’s Vetting Keeps Missing This
A natural question is how extensions engaged in active data theft managed to earn Google’s own “Featured” badge, a distinction meant to signal trustworthiness to users. A common technique behind these campaigns is delayed activation — an extension behaves entirely legitimately for weeks or months after publication, passing automated review and accumulating genuine positive reviews and install numbers, before a remote update quietly introduces the malicious data-collection behavior long after the extension has already earned the store’s trust signals, meaning the review that mattered happened before the malicious code ever existed, not after.
Does a high rating or “Featured” badge mean a Chrome extension is genuinely safe?
Not reliably — several of the extensions involved in recent large-scale data theft campaigns carried Google’s own “Featured” badge and strong user ratings at the exact time they were actively exfiltrating data. These trust signals reflect the extension’s behavior and reputation at the point they were last evaluated, not necessarily its current behavior, especially once delayed-activation malicious updates enter the picture.
3. How an Extension Gains This Much Access
The permission model browser extensions operate under is genuinely broader than most users realize when they click “install” without reading the permissions prompt. A common and often necessary permission request — “read and change all your data on websites you visit” — gives an extension the technical ability to see everything a user types, everything displayed on a page, and every cookie or session token active in that browser tab, which is precisely why a seemingly simple utility extension can technically access banking sessions, internal company tools, and authenticated business applications all at once, entirely independent of what the extension’s stated purpose actually is.
4. The Real Business Exposure This Creates
For a business, the risk here extends well past any individual employee’s personal browsing privacy. A single employee installing a compromised extension on a work device can expose session tokens for internal business tools, customer relationship management systems, cloud infrastructure dashboards, and financial platforms — anything the employee is logged into during a normal workday — turning one careless click on a browser extension into a genuine path toward the exact kind of credential-based compromise that’s driven so many of this year’s largest breaches.
Can a malicious browser extension access company systems even if the employee only uses it for personal browsing?
Yes, if the extension is installed on the same browser profile used for work — extension permissions typically apply broadly across all tabs and sites visited in that browser, not just the sites the extension was intended for. This is exactly why separating personal and business browser profiles, and restricting extension installation on business profiles specifically, is a meaningful control worth implementing.
5. The AI Impersonation Angle
A particularly effective and current variant of this threat has emerged riding the popularity of AI assistants specifically. Extensions falsely marketed as official companions or productivity add-ons for popular AI tools like ChatGPT and Claude have been found stealing conversation histories from over 900,000 users, an especially sensitive category of data given how often people paste proprietary business information, draft communications, and internal strategy discussions directly into AI chat interfaces — a stolen conversation history from an AI assistant can expose exactly the kind of confidential business context a company would never knowingly hand to a third party.
6. Warning Signs an Extension May Be Malicious
While no checklist catches every case, a handful of patterns show up consistently across the extensions involved in these campaigns. Requesting broad permissions — access to all websites — that go far beyond what the extension’s stated function would reasonably require, a recent ownership or developer change on an extension that’s been established for years, a sudden update that doesn’t correspond to any new features announced, and a lack of a genuinely identifiable, accountable developer or company behind the listing are all worth treating as real red flags rather than dismissing as paranoia.
7. Common Mistakes
These mistakes recur across businesses with no formal browser extension policy.
- Trusting store badges and ratings as proof of safety: Treating “Featured” status or high ratings as a substitute for actual vetting.
- No centralized visibility into installed extensions: Having no way to audit what’s actually running across the organization’s browsers.
- Allowing unrestricted extension installation on work devices: Letting employees install anything without any review or approval process.
- Using the same browser profile for personal and business browsing: Letting personal-use extensions gain access to business sessions and tools.
- Never reviewing previously approved extensions: Missing malicious updates pushed to extensions long after initial approval.
- Overlooking AI-assistant-branded extensions specifically: Not recognizing this newer, high-risk category alongside more familiar extension threats.
How to Govern Extension Use Across Your Business
A practical sequence for reducing browser extension risk across an organization.
1. Audit Currently Installed Extensions
Get visibility into what’s actually running across your organization’s browsers.
2. Set an Extension Allowlist Policy
Require approval before employees install new extensions on work devices.
3. Separate Personal and Work Browser Profiles
Prevent personal-use extensions from accessing business sessions.
4. Review Permission Scope, Not Just Ratings
Check whether requested access matches the extension’s actual stated purpose.
5. Monitor for Ownership and Update Changes
Re-review previously approved extensions periodically, not just once.
6. Train Employees on Warning Signs
Build awareness of red flags beyond just store ratings and badges.
8. Final Thoughts: The Browser Is Part of Your Attack Surface
Most businesses spend real time and budget securing their servers, their applications, and their networks, while the browser sitting on every employee’s desktop — with direct access to every business tool that browser logs into — remains almost entirely ungoverned. With 37.4 million installs compromised in a single campaign and store trust signals proving unreliable as a safety indicator, treating browser extensions as a genuine, governed part of an organization’s attack surface, rather than a harmless personal productivity choice each employee makes on their own, is no longer optional for any business that takes its access-control posture seriously.
Not sure what’s actually running across your team’s browsers? Explore our technology consultancy services, review our pricing, or contact us for a browser and access-control review.
About Webtoz Solutions Team
Webtoz is a full-service web development, software engineering, and technology consultancy, helping businesses govern browser-level risk as part of a genuinely complete access-control strategy. Learn more about us, or get in touch to discuss your exposure.
Ready for a Browser Security Review?
Let Webtoz audit the extensions running across your team’s browsers and build the governance policy your access-control strategy is missing.
Get in Touch →