DEV Community

Cover image for A Fake Extension Passed Chrome's Review Process on the First Try
Short Lived
Short Lived

Posted on

A Fake Extension Passed Chrome's Review Process on the First Try

What the research found

A 2024 study built a working extension designed to access sensitive fields like passwords and card numbers, then submitted it through the normal Chrome Web Store review process. It passed. The same researchers scanned over 160,000 existing extensions on the store and found 28,000 held permission to access sensitive input fields, with 190 caught storing password values in their own variables. A separate check of the top 10,000 website login pages found that 1,000 of them, including Google.com and Cloudflare.com, stored passwords in plain, unencrypted text within the page source itself, readable in full by any extension with basic access.

A 2025 study measuring data minimization across about 200,000 extensions found 38 percent collected personal data reaching beyond what their stated functionality required. Another 2023 study cross-checked 47,200 extensions against their own published privacy policies and found 820 of them moving user data in ways that contradicted what they’d told users they do, with 525 pairs of privacy statements that contradicted each other within the same extension’s disclosures.


Why store review doesn’t catch most of this

Extension stores review submissions before publishing them, but the researchers behind a 2025 study of the Chrome Web Store’s own detection systems found a term for what happens next: concept drift. Malicious extensions evolve their behavior fast enough that classifiers trained on last year’s threats miss a meaningful share of this year’s. The same study found that commercial detection tools, the kind of scanner most people assume would catch this, did a poor job against known malicious extensions already confirmed by Google itself. Out of a fresh batch of over 35,000 extensions with no established history, the researchers still identified 68 that had already slipped past the vetting process undetected.


The practical takeaway

Extension count matters less than permission scope. Before installing anything, check what access it requests: an extension that wants to “read and change all your data on all websites you visit” carries reach into everything you type, including on your banking site. Open your browser’s extension list from time to time and remove anything you installed once and forgot about. An old, abandoned extension with broad permissions is the kind of thing that keeps working in the background long after you stopped thinking about it.

None of this means extensions are unsafe by nature. Most serve their stated purpose without incident. The issue is that store review and commercial scanning tools both have documented blind spots, which means the responsibility for checking permissions before installing sits with the user more than most people assume.


References

  1. Nayak, A., et al. “Experimental Security Analysis of Sensitive Data Access by Browser Extensions.” Proceedings of the ACM Web Conference, 2024. https://doi.org/10.1145/3589334.3645683

  2. Ling, Y., et al. “Essential or Excessive? MINDAEXT: Measuring Data Minimization Practices among Browser Extensions.” IEEE International Conference on Software Analysis, Evolution and Reengineering, 2024. https://doi.org/10.1109/saner60148.2024.00104

  3. Rosenzweig, B., et al. “It’s Not Easy: Applying Supervised Machine Learning to Detect Malicious Extensions in the Chrome Web Store.” ACM Transactions on the Web, 2025. https://doi.org/10.1145/3770852

Support Me on Ko-fi

Top comments (0)