No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Your Browser’s Extensions May Be Reading Your Passwords

February 10, 2026
in Protection
0
Your Browser's Extensions May Be Reading Your Passwords



We should all take common-sense steps to make sure our data stays safe and secure: use strong passwords with our accounts, and never reuse passwords; employ two-factor authentication on any account that offers it; and avoid clicking strange links in emails or text messages. But even when you follow all those rules, your personal data can still be at risk, strictly because the services you rely on aren’t following these rules themselves.

Some websites are putting your passwords at risk

Researchers at the University of Wisconsin-Madison discovered that a concerning number of browser extensions can access sensitive information that you enter into websites. Think passwords, credit card info, and Social Security numbers.

The team behind the discovery says they weren’t out looking to break a security story. Instead, they were “messing around with login pages,” specifically Google login pages, when they found that the sites’ HTML source code could see the passwords they entered in plain text. They turned their sights onto other websites—more than 7,000, reportedly—and found that about 15% of them were also storing sensitive information in plain text. That’s over 1,000 websites exposing important data.

That, of course, is not supposed to happen: When you enter sensitive data into a website—say, your password into Google’s login page—that site shouldn’t see your password at all. In short, the sites confirm your passwords through hashing algorithms—essentially, jumbling your password into a code that can be checked against the code the site stores on their end. They can then confirm you entered the right password without ever exposing the actual text. By storing things like passwords and Social Security numbers in plain text, those sites are exposing that data to anyone in the know.

Importantly, that includes browser extensions. The researchers claim that 17,300 Chrome extensions—or 12.5% of the extensions available for download on Google’s browser—have the permissions they need to view this sensitive plain text data. Think about the permissions you ignore when setting up a new extension, including permissions that give extensions full access to see and change what you enter on a webpage. Researchers didn’t expose any extensions by name, as the situation is not necessarily the fault of the extensions, but considering the scope, it’s possible some of the extensions you use can access sensitive information you enter in certain sites.

Again, legitimate extensions are not the priority: Instead, it’s the risk that a developer will create an extension with the intent of scraping sensitive info stored in plain text. While the researchers claim there are no extensions actively abusing this vulnerability yet, this isn’t a theoretical problem. Researchers created an extension from scratch that could pull this user data, uploaded it to the Chrome Web Store, and got it approved. They took it down immediately, but proved it’s possible for a hacker to get such a malicious extension on the official store. Even if the hacker didn’t make the extension, they could acquire a legitimate extension with an existing user base, adjust the code to take advantage of the vulnerability, and spring the updated extension on unsuspecting users. It happens all the time, and not just on Chrome.


What do you think so far?

How to protect your sensitive data from malicious browser extensions

Unfortunately, there’s little you can do to prevent these sites from storing your passwords, credit cards, and Social Security numbers in plain text. The hope is, following these discoveries, websites will improve their security and kill the vulnerabilities on their end. But that’s on them, not you.

There are some steps you can take to mitigate the damage, however. First, make sure to limit your use of browser extensions. The fewer extensions you use, the less likely it is you’ll use a malicious one. Use only extensions you fully trust, and frequently check in on updates. If the extension changes hands to a new developer, vet that new owner before continuing to use it. You could even disable your extensions when sharing sensitive information with websites. If you need to provide your Social Security number on an official web form, for example, you could disable your extensions to prevent them from reading the data.

You can also limit the data you share that could stored in plain text. If given the option, use passkeys instead of passwords, as passkeys don’t actually use any plain text data that hackers could steal. Similarly, use secure payment systems, such as Apple Pay or Google Pay, which don’t actually share your credit card information with the website you’re making a payment on. The name of the game is to avoiding typing out your sensitive details unless absolutely necessary—and then, reducing the parties who can see those details.



Editorial Team

Editorial Team

Related Posts

Google Is Rolling Out Two New Ways to Remove Your Sensitive Data From Search
Protection

Google Is Rolling Out Two New Ways to Remove Your Sensitive Data From Search

February 10, 2026
The Best Horror Movies on Netflix Right Now
Protection

The Best Horror Movies on Netflix Right Now

February 10, 2026
The Best Romantic Comedies Streaming on Netflix Right Now
Protection

The Best Romantic Comedies Streaming on Netflix Right Now

February 10, 2026
These New Beats Earbuds Are at Their Lowest Price Ever Right Now
Protection

These New Beats Earbuds Are at Their Lowest Price Ever Right Now

February 10, 2026
Scammers Are Sending Fake Invites With Malware
Protection

Scammers Are Sending Fake Invites With Malware

February 10, 2026
Five Ways to Make Your Phone Charge Faster
Protection

Five Ways to Make Your Phone Charge Faster

February 10, 2026
Load More
Next Post
Condé Nast Traveler

9 Best Cities in Europe for Every Kind of Traveler—From History Buffs to Foodies

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • What The Clarity Act Means For Ripple And XRP Once Done

    0 shares
    Share 0 Tweet 0
  • The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • I Used Monarch Money for 30 Days: Here’s What Happened

    0 shares
    Share 0 Tweet 0
  • The Morning Briefing: New COO for Old Mill and cyber security

    0 shares
    Share 0 Tweet 0

Latest News

Solana and XRP ETFs extend inflow streak while Bitcoin ETFs bleed $492m

Solana price eyes $57 fibonacci extension, bullish volume fades

February 10, 2026
0

Solana price remains under corrective pressure as fading bullish volume and unresolved liquidity below price open the door for a...

Condé Nast Traveler

How the NFL Charmed Londoners

February 10, 2026
0

With the NFL playing more games in places as far afield as Brazil, football has never been more globally popular....

More than 1 million homeowners are underwater on their mortgage — a 7-year high. Here’s what experts advise they do.

More than 1 million homeowners are underwater on their mortgage — a 7-year high. Here’s what experts advise they do.

February 10, 2026
0

About 1.1 million homeowners were underwater on their mortgages at the end of last year as home prices stalled, signaling...

Google Is Rolling Out Two New Ways to Remove Your Sensitive Data From Search

Google Is Rolling Out Two New Ways to Remove Your Sensitive Data From Search

February 10, 2026
0

Google announced two new ways for users to remove their sensitive information from the web Tuesday morning—or, at least, remove...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.