Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

287 Malicious Chrome Extensions Steal Browsing Data from 37.4 Million Users

A recent investigation has identified 287 Chrome extensions that reportedly transmit users’ browsing data to remote servers, affecting approximately 37.4 million installations. This constitutes about 1% of the global Chrome user base according to…

A recent investigation has identified 287 Chrome extensions that reportedly transmit users’ browsing data to remote servers, affecting approximately 37.4 million installations. This constitutes about 1% of the global Chrome user base according to estimates.

The researchers employed an automated testing pipeline to identify extensions with data-leaking behavior. Chrome was run within a Docker container, with all browser traffic routed through a man-in-the-middle (MITM) proxy. The team visited specific web addresses to detect data leakage patterns, focusing on the actual network activity of the extensions rather than their descriptions or permissions.

The findings, including a detailed report and an HTML version, are available on a public GitHub repository .

The study measured data leakage using a metric defined as: bytes_out = R ⋅ payload_size + b . If R ≥ 1.0 , the extension was considered "definitely leaking," while 0.1 ≤ R < 1.0 indicated probable leakage, warranting further manual review.

This constitutes about 1% of the global Chrome user base according to estimates.
Emily Carter · Thehackingpost

The scanning process required approximately 930 CPU-days, with each extension taking an average of 10 minutes to analyze. The researchers refrained from publishing full implementation details to prevent extension developers from adapting their tactics to evade detection.

The extensions were found to be collecting data for various entities, ranging from well-known analytics firms to lesser-known actors. The report mentions organizations like Similarweb, "Big Star Labs," Curly Doggo, and Offidocs, as well as multiple minor brokers.

Beyond privacy issues, leaked URLs can contain sensitive information such as personal identifiers, password reset links, document names, and internal paths, which could be exploited in targeted attacks. The researchers also set up a honeypot with "honey URLs" to monitor subsequent access attempts, noting activity from IP ranges linked to entities such as Kontera, HashDit, and Blocksi AI Web Filter.

Advertisement

Remove extensions that are unfamiliar or no longer in use. Choose extensions from well-known publishers with transparent privacy policies. Review extension permissions, particularly those that can read and change data on all websites visited. Monitor for unusual network activity or browser performance issues after installing extensions. In organizational settings, limit extension installations through administrative policies and allowlist vetted add-ons.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories