No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

More Than Half of Browser Extensions Pose Security Risks

August 23, 2023
in Protection
0
informa



Many browser extensions that organizations permit employees to use when working with SaaS apps such as Google Workspace and Microsoft 365 have access to high levels of content and present risks like data theft and compliance issues, a new study has found.

Researchers at Spin.AI recently conducted a risk assessment on some 300,000 browser extensions and third-party OAuth applications in use within enterprise environments. The focus was on Chromium-based browser extensions across multiple browsers such as Google’s Chrome and Microsoft’s Edge.

High-Risk Extensions

The study showed 51% of all installed extensions were high risk and had the potential to cause extensive damage to the organizations using them. The extensions all had the ability to capture sensitive data from enterprise apps, run malicious JavaScript, and surreptitiously send protected data including banking details and login credentials to external parties.

Most extensions — 53% — that Spin evaluated were productivity-related extensions. But the worst — from a security and privacy standpoint at least — were browser extensions in use within cloud software development environments: Spin assessed 56% of them as high security risks.

“The main takeaway for organizations from this report is the significant cybersecurity risks associated with browser extensions,” says Davit Asatryan, one of the authors of a report, released this week. “These extensions, while offering various features to enhance user experience and productivity, can pose serious threats to data stored in browsers such as Chrome and Edge, or SaaS data stored in platforms like Google Workspace and Microsoft 365,” he says.

One example is a recent incident where a threat actor uploaded a browser extension that purported to be the legitimate ChatGPT browser add-on but was in reality a Trojan horse that hijacked Facebook accounts. Thousands of users installed the extension and promptly had their Facebook account credentials stolen. The compromised accounts included several thousand business accounts.

Google quickly removed the weaponized extension from its official Chrome Store. But that has not stopped others from freely uploading other ChatGPT extensions to the same store: Spin found more than 200 ChatGPT extensions on the Chrome webstore in August, compared to just 11 in May.

Lax Controls

Spin’s analysis showed that organizations with over 2,000 employees have an average of 1,454 installed extensions. The most common among these were productivity-related extensions, tools that helped developers, and extensions that enabled better accessibility. More than one-third (35%) of these extensions presented a high risk, compared to 27% in organizations with fewer than 2,000 employees.

One startling takeaway from Spin’s report is the relatively high number of browser extensions — 42,938 — with anonymous authors that organizations appear to be freely using without considering any potential security pitfalls. The statistic is especially concerning given how easily anyone with malicious intent can publish an extension, says Asatryan. Making matters worse is the fact that in some cases, the browser extensions that organizations are using were sourced from outside an official marketplace.

“Companies also sometimes build their own extensions for internal use and upload them,” Asatryan says. “However, this may introduce additional risk, as extensions from these sources might not go through the same level of scrutiny and security checks,” as those available in official stores.

Spin found that browsers can be bad from inception or sometimes acquire malicious qualities via automatic updates. That can happen when an attacker infiltrates an organization’s supply chain and inserts malicious code into a legitimate update. Developers can also sell their extensions to other third-parties who might then update it with malicious capabilities.

Another factor that organizations need to consider is how a browser extension might use its permissions to behave in unexpected ways. “For example, an extension could obtain ‘identity’ permission and then use the ‘webrequest’ permission to send this information to a third-party,” Asatryan says.

It’s important for organizations to establish and enforce policies based on third-party risk management frameworks, he notes. They need to assess extensions and applications for operational, security, privacy, and compliance risks, and consider implementing automated controls that allow or block extensions based on organizational policies.

“We recommend that organizations evaluate browser extensions before installing them by considering factors such as the scope of permissions requested by the extension, the developer’s reputation, and disclosure of security or compliance audits,” Asatryan says. Regular updates and maintenance are important as are user reviews and ratings, and any history of data breaches or security incidents.

Editorial Team

Editorial Team

Related Posts

Apple Watch Bands Are 70% Off Right Now
Protection

Apple Watch Bands Are 70% Off Right Now

September 18, 2025
Garmin’s Venu 4 Has a New Fitness Coach and a Flashlight
Protection

Garmin’s Venu 4 Has a New Fitness Coach and a Flashlight

September 17, 2025
My Favorite Amazon Deal of the Day: The 13-Inch M4 MacBook Air
Protection

My Favorite Amazon Deal of the Day: The 13-Inch M4 MacBook Air

September 17, 2025
This 3-in-1 Eufy Smart Lock Is $110 Off Right Now
Protection

This 3-in-1 Eufy Smart Lock Is $110 Off Right Now

September 17, 2025
You Can Get a Lifetime License to Windows 11 Pro for $13 Right Now
Protection

You Can Get a Lifetime License to Windows 11 Pro for $13 Right Now

September 17, 2025
How to Fix 'Tilted' Dark Mode App Icons in iOS 26
Protection

How to Fix ‘Tilted’ Dark Mode App Icons in iOS 26

September 16, 2025
Load More
Next Post
Seeking up to 9% Dividend Yield? Here Are 2 Dividend Stocks Billionaire Bill Miller Is Holding for Income Growth

Seeking up to 9% Dividend Yield? Here Are 2 Dividend Stocks Billionaire Bill Miller Is Holding for Income Growth

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Meet the billionaire with close royal ties behind Trump’s tariffs: How Scott Bessent made his name by almost bankrupting British homeowners but could now be the UK’s economic lifeline

    0 shares
    Share 0 Tweet 0
  • My Favorite Amazon Deal of the Day: The 13-Inch M4 MacBook Air

    0 shares
    Share 0 Tweet 0
  • Chris Gilchrist: Saying goodbye to 50 years in financial services – what I will and won’t miss

    0 shares
    Share 0 Tweet 0
  • UBS AM: Private credit ‘bubble’ fears overblown

    0 shares
    Share 0 Tweet 0

Latest News

The Morning Briefing: Royal London, Aviva dominate pensions and SIPPs; Guardian appoints Gower Wisdom as COO

The Morning Briefing: Royal London, Aviva dominate pensions and SIPPs; Guardian appoints Gower Wisdom as COO

September 18, 2025
0

Good morning and welcome to your Morning Briefing for Thursday 18 September 2025. To get this in your inbox every...

BDACS unveils KRW-backed stablecoin KRW1 on Avalanche

BDACS unveils KRW-backed stablecoin KRW1 on Avalanche

September 18, 2025
0

Key Takeaways BDACS has launched KRW1, the first Korean won-backed stablecoin on the Avalanche blockchain. KRW1 is fully backed by...

Easy investing and ready-made portfolios

How to lock into 5.5% interest for 30 years with gilts or make a quick tax-free profit: INVESTING SHOW

September 18, 2025
0

By SIMON LAMBERT, THIS IS MONEY PUBLISHER Updated: 03:21 EDT, 18 September 2025 --> --> --> While markets have wobbled...

21 Best Things to Do in San Diego, From Museum Visits to Scenic Hikes

21 Best Things to Do in San Diego, From Museum Visits to Scenic Hikes

September 18, 2025
0

Every review on this list has been written by a Condé Nast Traveler journalist who knows the destination and has...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.