1080*80 ad

Chrome extensions amassing 6 million installs harbor concealed tracking code

Popular Chrome Extensions Found to Contain Hidden Tracking Code, Affecting Millions of Users

Millions of web users rely on browser extensions to enhance their online experience, adding features for productivity, customization, or fun. However, a recent discovery highlights a significant risk lurking within seemingly innocent add-ons: hidden tracking code designed to secretly profit from users’ browsing activities. Security researchers have uncovered several Chrome extensions with a combined 6 million installations that were quietly redirecting users through affiliate links.

This deceptive practice works by intercepting clicks on websites like e-commerce platforms. Instead of going directly to the intended page, the user is briefly sent through an affiliate link operated by the extension creator. This action drops a tracking cookie on the user’s browser. If the user then makes a purchase on that site, the extension operator earns a commission, even though the user had no knowledge of the tracking or redirection.

The scale of this operation is concerning, with the affected extensions being quite popular. While they appeared to offer legitimate functionality like weather forecasts, screen recording, or PDF tools, their true hidden purpose was to generate revenue through undisclosed affiliate schemes. This not only compromises user privacy but also consumes bandwidth and processing power, potentially slowing down the browsing experience.

Upon being notified, the platform provider took action, removing some of the identified extensions from the official store. However, others reportedly remained available, underscoring the ongoing challenge of policing add-ons in large marketplaces. Users who had these extensions installed prior to removal would still have the problematic code unless they manually uninstall them.

This incident serves as a critical reminder about the importance of browser security. Users should exercise caution when adding extensions. Always review the permissions an extension requests before installing it. Be wary of extensions asking for broad access to websites you visit. It is also advisable to install extensions only from official, trusted sources and to regularly audit the extensions installed in your browser, removing any that are no longer needed or seem suspicious. Protecting your online activity starts with understanding what tools you are adding to your digital environment. Stay vigilant and keep your browsing secure.

Source: https://www.bleepingcomputer.com/news/security/chrome-extensions-with-6-million-installs-have-hidden-tracking-code/

900*80 ad

      1080*80 ad