Skip to main content
  1. Home
  2. Computing
  3. News

Research reveals how these simple Chrome extensions are hawking your privacy

By stealing your clipboard data, hijacking searches and impersonating popular tools

Add as a preferred source on Google
malicious-google-chrome-extensions-on-web-store
Chris DeGraw / Digital Trends

Some of the most harmless-looking Chrome extensions are doing far more than they promise, and new research shows just how easily everyday tools can turn into privacy risks.

Security researchers warn that even basic extensions offering new tab pages, parental controls, or cleaner search results have been caught quietly spying on users, hijacking clipboards, and impersonating trusted brands, all while sitting inside Google Chrome‘s official Web Store.

When helpful Chrome extensions turn hostile

According to a detailed analysis from Symantec researchers, several extensions with more than 100,000 user base were found engaging in behavior that goes well beyond their stated purpose.

One example, called Good Tab, presents itself as a customizable new tab extension with weather and news. Behind the scenes, it quietly gives a remote website permission to read and write everything copied to a user’s clipboard, without clearly telling them. That means passwords or cryptocurrency wallet addresses could be hijacked while users are none the wiser.

Recommended Videos

A troubling case highlighted in the research involves outright impersonation. An extension called DPS Websafe claimed to deliver ad-free search results, but instead hijacked searches and tracked users’ activity.

To build trust, it copied the branding and iconography of Adblock Plus, a well-known and legitimate tool. Once installed, it quietly rerouted searches through its own servers, opening the door to tracking, monetization, and potential manipulation of results.

Another one called Children Protection marketed itself as a parental control tool. However, it was found capable of harvesting browser cookies for session hijacking and executing remote code pushed from external servers. Such behavior is typically associated with malware rather than family safety software.

Meanwhile, another browser extension called Stock Informer presents itself as a simple market and currency tracking tool, but researchers found that it quietly hijacks users’ searches and redirects them through monetization services without clear disclosure.

The extension also contains a serious security flaw that could allow attackers to run code inside the browser, turning a basic stock tracker into a real privacy risk. These findings also echo past cases where popular Chrome add-ons like Honey faced scrutiny over its scammy practices.

Researchers say the most unsettling part is that all of these extensions passed through Google’s vetting process and were available on the Chrome Web Store. While some have since been removed, others remain accessible at the time of writing.

The takeaway is simple but uncomfortable. Just because an extension looks useful or verified does not mean it is safe. Hence, users should think twice before installing extensions and handing over access to their browser and data.

Manisha Priyadarshini
Manisha Priyadarshini is a tech and entertainment writer with over nine years of editorial experience.
Lenovo’s next ThinkBook looks unbelievably thin in this leak
Say hello to Aeroblade, the ThinkBook that could redefine how thin a laptop can get.
Lenovo ThinkBook Aeroblade front view

Lenovo might have a new obsession, and it's all about being thin. Windows Latest got its hands on marketing images of an unannounced Lenovo laptop, and buried in the files is a name we've never seen before: Aeroblade. The device itself is clearly branded as a ThinkBook, so this could launch as the ThinkBook Aeroblade.

If you're not familiar, ThinkBook sits just below the premium ThinkPad lineup and is built for small and medium businesses who want that ThinkPad look without the ThinkPad price tag.

Read more
Apple fixed three Mac Screen Sharing flaws, and now it’s patching another one
macOS 26.6.1 arrives roughly 10 days after Apple shipped three separate Screen Sharing security fixes in macOS 26.6.
MacBook Pro on Table

Apple has released macOS Tahoe 26.6.1 to fix a Screen Sharing vulnerability that could let an attacker on the same network authenticate without valid credentials.

The timing makes this update more interesting than its small version number suggests. Apple’s security notes for macOS 26.6, released July 27, already listed three separate vulnerabilities affecting Screen Sharing Server.

Read more
Dell’s iconic XPS lineup may be heading into Google’s Googlebook ecosystem
Dell's iconic XPS lineup may be heading to Google's laptop platform for the first time.
Googlebook featured image.

A fresh benchmark leak suggests Dell is quietly building its first Googlebook under the XPS name, joining Lenovo and Asus as the hardware partner for Google's upcoming laptop platform (via Chrome Unboxed).

The leak trail started with an internal board codenamed "Mica" showing up in Chromium's development pipeline. It was tied to Qualcomm's "Bluey" architecture built specifically for Snapdragon X-series Googlebooks. 

Read more