Most people treat browser extensions the way they treat smoke detector batteries - install once, forget indefinitely, assume everything is fine. Extensions sit in a privileged position inside your browser, with access to page content, cookies, form data, and in many cases your full browsing history. And unlike apps on a phone, they receive almost no ongoing scrutiny from users after the initial install.

This isn’t a theoretical risk. In 2023, a widely-used Chrome extension called “PDF Toolbox” was found to contain hidden code that could inject arbitrary JavaScript into any page a user visited. It had over two million installs. The extension had passed Chrome Web Store review and sat quietly on users’ machines for an extended period before a researcher flagged it. Google removed it, but the broader pattern - legitimate-looking extension, large install base, malicious payload - has repeated itself multiple times across both Chrome and Firefox ecosystems.

The Acquisition Problem Is Getting Worse

The most underreported angle here isn’t malware masquerading as extensions from the start. It’s acquisition. A developer builds a useful tool, grows an audience of a few hundred thousand users, then sells the extension to a third party. The new owner inherits those users - and their permissions - and can push an update that adds data collection or ad injection. Users rarely notice because the extension still works exactly as before. The change happens silently in the background.

Chrome and Firefox both technically require extensions to disclose permission changes, but the prompts are easy to dismiss and most users have trained themselves to click through anything that interrupts their workflow.

What “Minimal Permissions” Actually Means in Practice

Extension permission models were supposed to solve this. The idea is that an extension should only request what it needs - a dark mode tool shouldn’t need access to your tabs, a coupon finder shouldn’t need to read your clipboard. But enforcement is inconsistent, and the line between “needed for functionality” and “useful for data collection” is genuinely blurry in ways that make review difficult.

Some extensions legitimately need broad access. A password manager has to read page content to fill fields. A reading-mode extension has to strip and reformat entire pages. The permissions that make an extension powerful are the same ones that make it dangerous if compromised.

The Audit Nobody Does

Opening chrome://extensions or about:addons and actually reviewing what’s installed takes about four minutes. Most people have never done it since their first install.

The extensions you installed for a job you no longer have, the site-specific tools for services you stopped using, the “just for one task” utility from 2022 - they’re all still running, still holding whatever permissions you granted them, still receiving updates from developers you’ve never thought about since. Whether those developers still own the extension, or sold it, or abandoned it entirely, is information you probably don’t have.