Malicious Browser Extension
Also known as: Rogue browser extension, Malicious Chrome extension, Over-permissioned extension, Browser add-on abuse
An extension that looks useful but holds broad permissions it does not need, letting it read pages, capture sessions and send data to an outside host from inside a trusted browser.
Watch it in 60 seconds
How it works
A malicious browser extension is add-on code that runs inside the browser with the user's privileges and abuses what it is allowed to see. Some are harmful from the first release; others begin as honest tools and turn harmful after a sale, an account takeover at the publisher, or a hostile update.
The power comes from permissions. An extension that can read and change every site, view browsing activity or access cookies sits inside the user's authenticated sessions, past the sign-in page and past multi-factor checks already completed. That is why a flashlight-style utility asking for access to all sites deserves suspicion.
Because extensions update silently, the code a team reviewed last month may not be the code running today. Trust has to be tied to a controlled list and a known update source, not to a one-time glance at a store listing.
Defence is mostly governance plus visibility. Analysts inventory installed extensions, inspect permissions and update URLs, and look for traffic to hosts the extension has no business contacting. Organisations then allow only approved extensions and block the rest through managed browser policy.
Walk through it
- 1The browser alert
- 2Read the permissions
- 3Find the outbound host
- Scope who has it installed
- Contain and allowlist
Browser management raised an alert on a finance laptop: a newly installed extension with unusually broad access. Read the alert before touching anything. The extension name sounds harmless, so the permissions are what matter.
New extension flagged: PDF Quick Tools
Device: FIN-LT-0231 User: a.moreno@fabrikam-logistics.example
Installed: today 09:12, source: user-initiated from the public store
Not on the approved extension list. Policy action: report only.
Rule hit: requests access to all sites and browsing activity.
Spot it
- Extension installed from the public store that is not on the approved list, especially with access to all sites.
- Update URL that is not the official store, or a sudden version change shortly after an ownership or publisher change.
- Permissions that do not fit the stated purpose, such as cookies and web request access for a file converter.
- Repeated POST requests with large bodies from managed browsers to a newly seen or uncategorised host.
- Session activity for a user from an unfamiliar location or device soon after the extension appeared.
Browser management inventory
ts=2026-10-11T09:12:38Z device=FIN-LT-0231 event=extension_installed name="PDF Quick Tools" id=hkfm0000examplepdftools permissions=cookies,webRequest,tabs,<all_urls> approved=falseWeb proxy
ts=2026-10-11T09:14:05Z user=a.moreno src=FIN-LT-0231 method=POST host=collect.stat-metrics-cdn.example bytes_out=48211 category=uncategorised action=allowed
ts=2026-10-11T09:21:19Z user=a.moreno src=FIN-LT-0231 method=POST host=collect.stat-metrics-cdn.example bytes_out=51730 category=uncategorised action=allowedkqlLarge POSTs to hosts not seen before in the last 30 days
ProxyLogs
| where Method == "POST" and BytesOut > 20000
| summarize First=min(Timestamp), Hits=count(), Users=dcount(User) by DestinationHost
| where First > ago(1d)
| order by Hits descNewly seen destinations with repeated uploads are a starting point. Expect some benign analytics hosts; confirm with the browser inventory.
splDevices with an unapproved extension holding all-sites access
index=browser_inventory event=extension_installed approved=false permissions="*<all_urls>*"
| stats values(name) as extensions, min(_time) as first_seen by device, userStop it
Allowlist extensions through enterprise policy
Block all extensions by default and permit only a reviewed list, pushed by managed browser policy. A user then cannot install a new add-on from the public store, which removes the whole class of surprise installs.
Apply least privilege and review changes
Approve an extension only after checking that its permissions match its purpose and that its update source is the official store. Re-review when the version, publisher or permissions change, because silent updates can alter behaviour after approval.
Watch the traffic and shorten session lifetime
Alert on uploads to newly seen hosts from managed browsers, and use short-lived sessions with device-bound tokens so any stolen cookie loses value quickly. Visibility catches what a one-time review misses.
Browser policy intent: block by default, allow a reviewed list
Hardened
ExtensionInstallBlocklist = *
ExtensionInstallAllowlist = [ approved-extension-id-1, approved-extension-id-2 ]
ExtensionInstallForcelist = [ corporate-extension-id ]Expressed as policy intent; use the exact policy names from your Chrome or Edge enterprise documentation.
- Enforce an extension blocklist of everything and an explicit allowlist, deployed through managed browser policy.
- Inventory installed extensions across all managed browsers and review permissions and update URLs on a schedule.
- Restrict installation to the official store and block extensions that use a custom update source.
- Alert on large uploads from managed browsers to uncategorised or newly registered hosts.
- Keep user sessions short and bind tokens to the device so a captured cookie expires quickly.
If it already happened
Disable and remove the extension from every device through browser management, block its update URL and the receiving host at proxy and DNS, and isolate the first affected machine if data theft is likely.
Find every user who installed it, revoke their sessions and tokens, and reset credentials for accounts used while it was active. Review those accounts for unusual sign-ins and changes.
Confirm the extension is gone and the policy allowlist is enforced, then restore normal access. Report the extension to the store operator for takedown.
Move to block-by-default policy, add the host and extension id to detections, and record how the install slipped past review.
Check yourself
1. Which extension permission most increases the risk that an add-on can read data from banking and email pages?
2. Which proxy-log finding best suggests an extension is sending data out?
3. What is the most effective organisation-wide control against users installing risky extensions?