The Hidden Price of 'Free'
Browser extensions are small software programs that add functionality to your web browser, and the sheer volume is staggering. In the first half of 2026 alone, nearly 50,000 new extensions were added to the Chrome Web Store. While many are useful and safe,
a significant number operate on a business model where the user is the product. If an extension is free, it's often making money by collecting and selling your data. Recent security reports have found hundreds of extensions, with tens of millions of users combined, that were leaking browsing history, spying on users, or actively stealing personal information. This data can include your browsing history, search queries, and even personal details entered into forms.
AI Enters the Audit
For years, malicious extensions have been a known problem, with some even acting as 'sleeper agents' that behave normally for years before an update turns them into spyware. Manually auditing the code for every extension is a nearly impossible task. This is where a new generation of AI-powered security tools comes in. These platforms, like ThreatXtension and others, use a combination of static code analysis, behavioural monitoring at runtime, and large language models to assess risk. They can automatically analyze an extension's permissions, scan for malicious code patterns targeting things like credential theft, and detect when an extension tries to send your data to an unauthorized server, providing a much-needed defense against these sophisticated threats.
What the Audits Uncovered
The findings from these AI-enhanced audits are concerning. One investigation found that two-thirds of AI-powered extensions collect user data, with a large portion harvesting personally identifiable information (PII) like passwords and financial details. Another report identified 287 extensions with over 37 million installs that were actively leaking user browsing history to more than 30 different third-party companies. The data being collected is extensive, ranging from authentication data and financial information to user activity like keystrokes and even personal communications in emails and chats. In one recent case from August 2026, a new AI extension called Kaito Pulse was flagged for its ability to track detailed user activity on social media platform X, including every post viewed, click, search, and bookmark.
The Usual Suspects
While any extension can be a risk, certain categories appear more frequently in security reports. Free VPNs, ad-blockers, and media-related tools are often highlighted. For example, a 2026 report from LayerX Security identified 82 popular Chrome extensions that openly stated in their privacy policies that they reserve the right to sell user data, affecting at least 6.5 million users. This group included 12 ad-blocking extensions with over 5.5 million users and 24 media-related extensions that tracked viewing habits across streaming platforms. These tools often masquerade as useful utilities while their primary function is to monetize your web activity. Because official browser stores can be slow to remove problematic extensions, millions of users can remain at risk.
How to Protect Yourself
Protecting your privacy doesn't require you to abandon extensions entirely, but it does demand vigilance. First, conduct a personal audit. Remove any extensions you no longer use or don't recognize. For the ones that remain, be ruthless about permissions. An extension that customizes your cursor does not need permission to read data on every website you visit. Check the permissions in your browser's extension settings and disable any that seem excessive. Before installing a new extension, read user reviews and check the developer's reputation. Look for extensions from well-known security firms or those with a clear, privacy-focused business model. You can also use privacy-enhancing extensions like the EFF's Privacy Badger, which uses algorithmic methods to identify and block trackers automatically.














