Urgent.News

What's breaking now, across thousands of outlets.

Tech

The Extension You Vetted Is Not the One That Auto-Updates

We tell people to be careful which browser extensions they install. Check the reviews, look at the permissions, prefer the ones with a name behind them. It is good advice, and it quietly assumes something that is not true: that the extension you install is the extension you keep. It is not. Extensions auto-update, silently, in the background, from whoever controls the listing today - which is not…

Browser extensions are widely used, but they come with a hidden risk: they can silently update from the control of the person who listed them, not the person who initially installed them. This auto-update process does not require user approval, allowing an extension to change hands and potentially evolve into something malicious without the user's knowledge.

In 2025, a Chrome extension called AI Sidebar with DeepSeek, ChatGPT, Claude and more was flagged for scraping conversations and sending them to external domains. Despite being pulled from the Chrome Web Store in January 2026, it returned by August 2026 through Google's CDN. This new version, 1.7.3.0, was found to not only scrape but also monetize user data by exploiting a Chrome quirk that allows an extension to earn an affiliate commission even after it's been uninstalled.

This phenomenon highlights the trust issue in extension updates: users install a popular, well-reviewed extension and later find it behaving differently without their consent. Extensions are essentially listings owned by someone, and this ownership can transfer through sales, which the browser store does not notify users about. Security firm Socket documented a surge of this practice in 2026, where extensions sold from their original creators were injected with code to steal credentials and cryptocurrency.

Once granted permissions, an extension does not ask for additional ones, even if it starts using them for new purposes. The Manifest V3 update, meant to enhance security, did not significantly change this trust model. Instead, it made remote code exploitation slightly harder but left vulnerabilities like service workers opening affiliate tabs on update.

For users, reducing the number of extensions, uninstalling unused ones, and separating profiles by risk can help mitigate exposure. For extension builders, it's crucial to recognize that selling a listing transfers users' trust to the new owner, and it's ethically important to inform users about this transfer. Chrome's 2026 enforcement of stricter rules around data collection and removals of malicious extensions helps, but the core issue lies in the supply-chain nature of extension updates, which remains largely unchecked.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Friday 4 September →